<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:36:42.363-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:9999" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436"/>
        <description>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:35.831-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.675-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9999 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:23.622-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:01.633-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:39507"/>
            <criterion comment="kdebase-devel is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:40464"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40335"/>
            <criterion comment="kdebase-devel is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40374"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9998" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4245"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:38.878-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.493-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9998 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:42.696-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:01.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9996" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.334-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9996 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:02.908-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:24:00.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33627"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34238"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34171"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33767"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34147"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34640"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34202"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34749"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34767"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34660"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34728"/>
            <criterion comment="krb5 is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34350"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34575"/>
            <criterion comment="krb5-server is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34729"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34195"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9995" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1056"/>
        <description>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:05.980-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.348-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9995 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:25.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:59.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9994" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2210"/>
        <description>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:16.910-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.828-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.694-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9994 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:07.247-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:59.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38621"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38710"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38897"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38330"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38382"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38913"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38781"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38614"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38727"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38447"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38465"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38839"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38248"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38879"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38157"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38757"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9993" version="5" class="vulnerability">
      <metadata>
        <title>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2672"/>
        <description>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:27.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9993 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:10.379-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:58.813-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:31850"/>
          <criterion comment="lm_sensors is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:32360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9992" version="5" class="vulnerability">
      <metadata>
        <title>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626"/>
        <description>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:48.624-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.147-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9992 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:00.441-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:58.162-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9991" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102"/>
        <description>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:44.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:24.308-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.178-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9991 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:27.363-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:57.195-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33279"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33033"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33135"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32975"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33134"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32756"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33026"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33238"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33343"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32868"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33217"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33260"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33106"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33262"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33329"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32993"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33159"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33053"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33163"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33308"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32484"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33294"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33176"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32802"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32909"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33270"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33234"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33180"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32796"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33158"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33322"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33297"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33211"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33206"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33346"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33222"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33340"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33228"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33187"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33289"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33242"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33068"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33283"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33337"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:32984"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33352"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33122"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9990" version="5" class="vulnerability">
      <metadata>
        <title>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630"/>
        <description>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:18.827-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.779-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9990 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:26.346-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:56.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38892"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38222"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:37924"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38847"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38834"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38158"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38513"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38317"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38667"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38814"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9988" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6142"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.683-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.364-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9988 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:17.179-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:55.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el3" test_ref="oval:org.mitre.oval:tst:32449"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el4" test_ref="oval:org.mitre.oval:tst:33384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9986" version="5" class="vulnerability">
      <metadata>
        <title>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2177"/>
        <description>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.807-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.617-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9986 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:18.285-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:54.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9985" version="5" class="vulnerability">
      <metadata>
        <title>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223"/>
        <description>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:42.350-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.376-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9985 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:53.367-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:54.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="quagga is earlier than 0:0.96.2-11.3E" test_ref="oval:org.mitre.oval:tst:32541"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="quagga-devel is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32744"/>
            <criterion comment="quagga is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32471"/>
            <criterion comment="quagga-contrib is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9984" version="5" class="vulnerability">
      <metadata>
        <title>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3108"/>
        <description>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:59.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.994-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.859-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9984 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:57.379-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:53.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:35001"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34962"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34324"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35545"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35457"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35580"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35181"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35460"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35053"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9983" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3694"/>
        <description>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:34.640-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9983 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:56.841-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:53.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32443"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32730"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32800"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32566"/>
            <criterion comment="ruby is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32264"/>
            <criterion comment="irb is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32482"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32617"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32600"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32723"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32881"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32751"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32913"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32117"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32804"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9982" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292"/>
        <description>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:28.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:20.856-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:29.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9982 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:49.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:52.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39717"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39629"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39915"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39741"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:40003"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39901"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39326"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39580"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:40010"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39927"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39619"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39111"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39417"/>
            <criterion comment="php is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39899"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39642"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39821"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39461"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39627"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39886"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39848"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39908"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39883"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39544"/>
            <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39804"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39875"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39748"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39802"/>
            <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39053"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39854"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39980"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39581"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39954"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39018"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39463"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39634"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39436"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39969"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39664"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39913"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9979" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4352"/>
        <description>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:15.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9979 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:46.216-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:50.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9978" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2071"/>
        <description>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:57.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.204-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9978 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:27.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:50.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9976" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1519"/>
        <description>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.423-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.667-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9976 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:00.766-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:49.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" test_ref="oval:org.mitre.oval:tst:31246"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" test_ref="oval:org.mitre.oval:tst:31854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9975" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2475"/>
        <description>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.402-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9975 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:56.442-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:48.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.50-35.EL3" test_ref="oval:org.mitre.oval:tst:30464"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.51-9.EL4.5" test_ref="oval:org.mitre.oval:tst:33619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9973" version="5" class="vulnerability">
      <metadata>
        <title>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2374"/>
        <description>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:27:11.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.715-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9973 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:24.563-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:48.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bluez-libs is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37371"/>
            <criterion comment="bluez-utils-cups is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:37307"/>
            <criterion comment="bluez-utils is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:36921"/>
            <criterion comment="bluez-libs-devel is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37129"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bluez-libs is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:37391"/>
            <criterion comment="bluez-utils-cups is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37349"/>
            <criterion comment="bluez-utils is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37379"/>
            <criterion comment="bluez-libs-devel is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:36988"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9972" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592"/>
        <description>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:01.426-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.359-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9972 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:24.332-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:47.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9970" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1460"/>
        <description>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:29.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:16.878-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.648-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9970 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:05.931-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:46.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9967" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2834"/>
        <description>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:04.925-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:14.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9967 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:08.581-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:43.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34967"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34907"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34663"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34624"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34985"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34600"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35058"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34840"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34776"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34590"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35090"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35105"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34685"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34233"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34999"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34898"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35138"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34744"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34838"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34903"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34783"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35127"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35036"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35135"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35130"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34854"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34867"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35190"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34239"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34269"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35163"/>
            <criterion comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34429"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34318"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34522"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34715"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34987"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35152"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34733"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34947"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34830"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35107"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34895"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34353"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35096"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34629"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35089"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34887"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34939"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34988"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34591"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34737"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34412"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34871"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34717"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34942"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35019"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34969"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35129"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34980"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34548"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35098"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34983"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34904"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35206"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34571"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35157"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35006"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34919"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35196"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35104"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34449"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34768"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35222"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35111"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35231"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35237"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34488"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34457"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35232"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35235"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35194"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34862"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34938"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34706"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34766"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35172"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34709"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35079"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35080"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34726"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34972"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35101"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34674"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35094"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35137"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34909"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35201"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34989"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35225"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34978"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35038"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35198"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34866"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34918"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34874"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35203"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35211"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34963"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34932"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35151"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34242"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35217"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35027"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34687"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34666"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34639"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34834"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35238"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35072"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35082"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34878"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34330"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35063"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34592"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35109"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34705"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34515"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34792"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35068"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35132"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35188"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35128"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34875"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34788"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35158"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34970"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34996"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34349"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9966" version="5" class="vulnerability">
      <metadata>
        <title>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2786"/>
        <description>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:22.234-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9966 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:04.477-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:42.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9964" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3389"/>
        <description>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:24.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9964 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:32.583-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:41.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34755"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34336"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34784"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9963" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4986"/>
        <description>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:14.834-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9963 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:13.686-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:41.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9962" version="5" class="vulnerability">
      <metadata>
        <title>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225"/>
        <description>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:20.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9962 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:20.268-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:40.838-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32634"/>
            <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32130"/>
            <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32453"/>
            <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32516"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32587"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32475"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32414"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32296"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32306"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9961" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1157" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:11.827-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9961 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:17.007-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:40.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9959" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726"/>
        <description>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:56.212-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:19.416-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9959 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:24.426-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:38.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9958" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"/>
        <description>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:27.599-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.553-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9958 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:46.310-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:38.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39033"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:38392"/>
            <criterion comment="httpd is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39071"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:38759"/>
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:39047"/>
            <criterion comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:39098"/>
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:38182"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:38932"/>
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39149"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38625"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38971"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39108"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9957" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188"/>
        <description>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:10.245-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.645-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9957 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:15.930-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:37.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9955" version="5" class="vulnerability">
      <metadata>
        <title>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0798"/>
        <description>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:07.606-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9955 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:45.300-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:37.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.2-4" test_ref="oval:org.mitre.oval:tst:38604"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.3-2.el4_7.1" test_ref="oval:org.mitre.oval:tst:38456"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="acpid is earlier than 0:1.0.4-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9954" version="8" class="vulnerability">
      <metadata>
        <title>Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2800"/>
        <description>Memory leak in the seq_file implemenetation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.009-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9954 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:17.989-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:36.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9954 - Fixed typo in title and description of def:9954" date="2014-05-22T10:52:00.994-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T10:54:21.347-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:50.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9953" version="5" class="vulnerability">
      <metadata>
        <title>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3740"/>
        <description>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:36.571-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.852-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9953 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:12.405-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:36.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9951" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6107"/>
        <description>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:02.643-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9951 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:41.195-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:35.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="dbus-glib is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32768"/>
          <criterion comment="dbus-devel is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33345"/>
          <criterion comment="dbus-x11 is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33280"/>
          <criterion comment="dbus-python is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32745"/>
          <criterion comment="dbus is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9950" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3837"/>
        <description>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:29.260-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.762-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9950 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:48.603-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:34.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9949" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6056"/>
        <description>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:45.646-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.485-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:15.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9949 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:24.311-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:34.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9947" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2314"/>
        <description>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:08.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.674-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9947 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:36.218-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:33.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32465"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32618"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32497"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32527"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32392"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32719"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32621"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32195"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32628"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32601"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:31936"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32101"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31976"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32564"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32038"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32648"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31768"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32626"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31950"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32604"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32472"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9945" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829"/>
        <description>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9945 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:19.338-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:32.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9944" version="5" class="vulnerability">
      <metadata>
        <title>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906"/>
        <description>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:02.322-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:05.773-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9944 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:33.158-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:31.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39355"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39369"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39545"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39162"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39589"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39603"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39658"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39633"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39222"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39493"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39205"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9942" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397"/>
        <description>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:11.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.911-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9942 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:43.952-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:30.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:38235"/>
            <criterion comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:37467"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38180"/>
            <criterion comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38318"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9941" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147"/>
        <description>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:46.519-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.319-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:12.464-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9941 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:17.397-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:29.292-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9939" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3863"/>
        <description>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:58.147-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.812-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9939 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:05.798-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:28.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.7" test_ref="oval:org.mitre.oval:tst:37704"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-33.el4_7.1" test_ref="oval:org.mitre.oval:tst:37804"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" test_ref="oval:org.mitre.oval:tst:38101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9938" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452"/>
        <description>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:14.746-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.537-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9938 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:04.938-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:28.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:31361"/>
            <criterion comment="perl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:30931"/>
            <criterion comment="perl-CPAN is earlier than 2:1.61-89.10" test_ref="oval:org.mitre.oval:tst:30901"/>
            <criterion comment="perl-CGI is earlier than 2:2.81-89.10" test_ref="oval:org.mitre.oval:tst:31227"/>
            <criterion comment="perl-DB_File is earlier than 2:1.804-89.10" test_ref="oval:org.mitre.oval:tst:30945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" test_ref="oval:org.mitre.oval:tst:31049"/>
            <criterion comment="perl is earlier than 3:5.8.5-12.1" test_ref="oval:org.mitre.oval:tst:31120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9937" version="5" class="vulnerability">
      <metadata>
        <title>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4790"/>
        <description>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.969-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9937 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:46.269-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:27.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32934"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9934" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3811"/>
        <description>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:21.415-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:02.264-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:10.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9934 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:10.292-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:26.360-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9933" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304"/>
        <description>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:24.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9933 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:11.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:25.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9932" version="5" class="vulnerability">
      <metadata>
        <title>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0555"/>
        <description>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.862-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9932 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:41.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:25.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9929" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1526"/>
        <description>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&amp;" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:13.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.756-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.776-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9929 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:16.983-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:24.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31792"/>
          <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32571"/>
          <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32223"/>
          <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32554"/>
          <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32521"/>
          <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32568"/>
          <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32369"/>
          <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31728"/>
          <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32424"/>
          <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32510"/>
          <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32532"/>
          <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32174"/>
          <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32670"/>
          <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32705"/>
          <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32274"/>
          <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32683"/>
          <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32330"/>
          <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9927" version="5" class="vulnerability">
      <metadata>
        <title>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1856"/>
        <description>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:25.870-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9927 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:09.055-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:23.842-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9926" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:48.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9926 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:18.008-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:22.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9925" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005"/>
        <description>Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:56.373-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.151-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9925 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:39.777-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:22.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30471"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30355"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30877"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30918"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:30872"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31137"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31139"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31140"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9924" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:26.737-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.821-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9924 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:21.439-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:21.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9923" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:07.106-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.549-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9923 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:35.821-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:21.321-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gftp is earlier than 1:2.0.14-4" test_ref="oval:org.mitre.oval:tst:31807"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gftp is earlier than 1:2.0.17-5" test_ref="oval:org.mitre.oval:tst:31775"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9922" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0356"/>
        <description>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:19.288-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.214-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.246-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9922 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:42.919-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:20.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9921" version="5" class="vulnerability">
      <metadata>
        <title>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621"/>
        <description>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:02.374-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.700-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9921 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:10.871-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:20.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9920" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3934" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3934"/>
        <description>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.398-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.422-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9920 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:04.112-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:19.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9918" version="5" class="vulnerability">
      <metadata>
        <title>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1516"/>
        <description>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:56.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:04.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9918 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:15.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:18.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9915" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903"/>
        <description>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.900-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:55.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:03.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9915 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:41.759-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:17.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
            <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
            <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
            <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9912" version="5" class="vulnerability">
      <metadata>
        <title>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2941"/>
        <description>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.286-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.841-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9912 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:57.499-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-25.rhel3.7" test_ref="oval:org.mitre.oval:tst:32470"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.5" test_ref="oval:org.mitre.oval:tst:32787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9911" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.778-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.584-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9911 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:47.631-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9910" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461"/>
        <description>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:11.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.117-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9910 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:24.863-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:16.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9909" version="5" class="vulnerability">
      <metadata>
        <title>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0456"/>
        <description>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.573-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9909 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:27.127-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:15.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9908" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5023"/>
        <description>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:26.352-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.413-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9908 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:04.221-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:14.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9904" version="5" class="vulnerability">
      <metadata>
        <title>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377"/>
        <description>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:52.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9904 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:51.281-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:13.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.31-4.el3" test_ref="oval:org.mitre.oval:tst:34732"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.48-2.el4" test_ref="oval:org.mitre.oval:tst:34581"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="perl-Net-DNS is earlier than 0:0.59-3.el5" test_ref="oval:org.mitre.oval:tst:34803"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9903" version="5" class="vulnerability">
      <metadata>
        <title>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3806"/>
        <description>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:54.626-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.984-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9903 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:37.341-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:12.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9902" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:54.396-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.653-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.362-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9902 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:35.444-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:12.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9901" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5904"/>
        <description>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:15.902-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.155-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9901 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:50.219-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:11.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36188"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36478"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36125"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36428"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35983"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36049"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36310"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36246"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36377"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35967"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36113"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9900" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2785"/>
        <description>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:45.937-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:50.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9900 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:49.325-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:10.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37358"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37417"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37346"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36845"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37059"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37083"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36603"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37075"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37472"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36782"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37402"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37430"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37439"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37337"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36865"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36898"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.21.el4" test_ref="oval:org.mitre.oval:tst:36910"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37455"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36525"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37362"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36596"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37517"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37176"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37474"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37409"/>
            <criterion comment="devhelp is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37522"/>
            <criterion comment="yelp is earlier than 0:2.16.0-20.el5" test_ref="oval:org.mitre.oval:tst:37008"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37414"/>
            <criterion comment="firefox is earlier than 0:3.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37297"/>
            <criterion comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" test_ref="oval:org.mitre.oval:tst:37422"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9897" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415"/>
        <description>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:31.823-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:49.161-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.950-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9897 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:06.410-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:09.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9895" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3743"/>
        <description>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.550-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9895 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:25.810-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:08.472-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32037"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32699"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32588"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32852"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32383"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32971"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32748"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32946"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32537"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9893" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2024"/>
        <description>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:49.067-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.008-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9893 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:33.443-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:07.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9891" version="5" class="vulnerability">
      <metadata>
        <title>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620"/>
        <description>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:39.465-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:47.311-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9891 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:28.143-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:06.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9890" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0179"/>
        <description>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:15.752-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.859-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:54.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9890 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:56.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:06.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9889" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1238"/>
        <description>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:02.547-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.338-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9889 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:07.827-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:05.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9888" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.587-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.969-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9888 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:16.855-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:04.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37860"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37771"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:38036"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37841"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37839"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37940"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:38044"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37640"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37694"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9887" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2264"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:35.727-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.787-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.405-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9887 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:05.361-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:04.530-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9885" version="5" class="vulnerability">
      <metadata>
        <title>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5174"/>
        <description>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:06.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.177-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9885 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:10.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:03.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9884" version="5" class="vulnerability">
      <metadata>
        <title>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0780"/>
        <description>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:19.280-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:44.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9884 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:32.650-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:02.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9880" version="5" class="vulnerability">
      <metadata>
        <title>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6119"/>
        <description>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:52.977-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.402-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9880 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:23.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:01.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9879" version="5" class="vulnerability">
      <metadata>
        <title>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4224"/>
        <description>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:28.753-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.102-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9879 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:26.551-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:23:00.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:34380"/>
            <criterion comment="kdebase-devel is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:35343"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35165"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35252"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:34844"/>
            <criterion comment="kdebase-devel is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:35321"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35316"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35293"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:34994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9878" version="6" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled causes the skb structure to be freed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1188"/>
        <description>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:54.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:42.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.003-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9878 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:15.967-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:59.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40272"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40483"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40310"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40062"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40096"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39895"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40165"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40131"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40380"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39955"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40115"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39718"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40363"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40151"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40182"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40070"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40313"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40302"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39440"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39472"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40090"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39519"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39840"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9875" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:41.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9875 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:54.928-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:58.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9873" version="5" class="vulnerability">
      <metadata>
        <title>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947"/>
        <description>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:56.724-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:40.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.006-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9873 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:20.196-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:57.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9872" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5018"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:32.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.910-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:47.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9872 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:02.598-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:56.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9870" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0736"/>
        <description>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:15.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9870 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:18.940-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:55.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9869" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4330" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4330"/>
        <description>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.391-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9869 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:26.730-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:55.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:33011"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:32323"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:33025"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:32974"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9868" version="5" class="vulnerability">
      <metadata>
        <title>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5500"/>
        <description>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.346-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9868 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:23.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:54.677-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
          <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9866" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0766"/>
        <description>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:24.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.111-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:45.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9866 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:09.242-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:53.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31514"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31448"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31593"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31548"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9865" version="5" class="vulnerability">
      <metadata>
        <title>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2811"/>
        <description>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:37.447-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:44.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9865 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:51:56.667-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:53.101-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9863" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2376"/>
        <description>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.866-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.715-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9863 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:21.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:51.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9861" version="5" class="vulnerability">
      <metadata>
        <title>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1721"/>
        <description>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:32.582-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9861 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:38.936-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:50.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35185"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35067"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35028"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:34649"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35113"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cyrus-sasl-ntlm is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35092"/>
            <criterion comment="cyrus-sasl-sql is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35100"/>
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34748"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34948"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35102"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34645"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34338"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9860" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.483-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.889-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9860 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:23.820-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:50.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37666"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37742"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37538"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37806"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37593"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37167"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37819"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37707"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37868"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37115"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:36966"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37758"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37686"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37927"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9859" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063"/>
        <description>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:17.627-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.122-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9859 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:47.992-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:49.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40725"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40543"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40781"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40212"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40761"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40021"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tdb-tools is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40785"/>
            <criterion comment="libtdb-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:39928"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40808"/>
            <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40403"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40124"/>
            <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40792"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40636"/>
            <criterion comment="libtalloc-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40508"/>
            <criterion comment="libtdb is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40589"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40500"/>
            <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40646"/>
            <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40660"/>
            <criterion comment="libtalloc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40439"/>
            <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40724"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40663"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40822"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40799"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40481"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:39867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9858" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2933"/>
        <description>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:13.577-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:34.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9858 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:40.490-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:48.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32711"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32166"/>
            <criterion comment="imap is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:31804"/>
            <criterion comment="imap-devel is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32091"/>
            <criterion comment="php is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32579"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32613"/>
            <criterion comment="imap-utils is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32441"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32425"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32107"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32695"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31742"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32509"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32606"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32503"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32185"/>
            <criterion comment="libc-client is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32375"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32639"/>
            <criterion comment="php is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32546"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32577"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32236"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32578"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32591"/>
            <criterion comment="libc-client-devel is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32344"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32707"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32547"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9857" version="5" class="vulnerability">
      <metadata>
        <title>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3732"/>
        <description>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:39.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.922-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.492-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9857 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:47.575-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:48.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.3" test_ref="oval:org.mitre.oval:tst:32025"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ipsec-tools is earlier than 0:0.3.3-6.rhel4.1" test_ref="oval:org.mitre.oval:tst:32632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9853" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1461"/>
        <description>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:12.258-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.072-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9853 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:24.939-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:47.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9852" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1769"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.818-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9852 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:54.383-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:46.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" test_ref="oval:org.mitre.oval:tst:31585"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" test_ref="oval:org.mitre.oval:tst:31556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9851" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1423"/>
        <description>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:32.959-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.531-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.925-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9851 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:43.147-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:46.327-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36659"/>
            <criterion comment="libvorbis is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36519"/>
            <criterion comment="libvorbis is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36439"/>
            <criterion comment="libvorbis is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9850" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938"/>
        <description>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:28.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.289-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.672-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9850 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:02.526-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:45.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9849" version="5" class="vulnerability">
      <metadata>
        <title>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2776"/>
        <description>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:02.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:31.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9849 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:45.820-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:45.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9846" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6063"/>
        <description>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:29.687-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.659-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:38.052-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9846 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:28.362-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:44.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36192"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36176"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36335"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36430"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35944"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36215"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36409"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35484"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35974"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35791"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36150"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9845" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1686"/>
        <description>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9845 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:56.618-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:43.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gedit is earlier than 1:2.2.2-4.rhel3" test_ref="oval:org.mitre.oval:tst:31476"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gedit is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31796"/>
            <criterion comment="gedit-devel is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9844" version="5" class="vulnerability">
      <metadata>
        <title>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2449" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2449"/>
        <description>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:45.232-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.235-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9844 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:56.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:43.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32706"/>
          <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9843" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4568"/>
        <description>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.251-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9843 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:26.610-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:42.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9842" version="5" class="vulnerability">
      <metadata>
        <title>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0423"/>
        <description>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:45.283-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.269-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9842 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:43.258-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:42.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9841" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6113"/>
        <description>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:20.400-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:28.758-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9841 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:33.180-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:41.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9839" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"/>
        <description>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:25.655-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.692-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:35.083-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9839 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:50.300-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:40.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35542"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35314"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35233"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35218"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35248"/>
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35491"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:34644"/>
            <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35275"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35533"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35714"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35722"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9838" version="5" class="vulnerability">
      <metadata>
        <title>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2873"/>
        <description>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.383-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.705-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9838 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:14.728-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:39.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30189"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30542"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30504"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30169"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29589"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29669"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30299"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30268"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9837" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1577"/>
        <description>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:55.117-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.162-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9837 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:48.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:39.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9836" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3243"/>
        <description>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:11.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.876-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9836 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:32.790-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:38.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9835" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0167"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9835 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:37.709-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:38.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9834" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175"/>
        <description>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:58.954-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9834 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:56.555-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:37.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9833" version="5" class="vulnerability">
      <metadata>
        <title>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1926"/>
        <description>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:38.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.908-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9833 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:06.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:37.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="util-linux is earlier than 0:2.12a-24.el4" test_ref="oval:org.mitre.oval:tst:38784"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9830" version="5" class="vulnerability">
      <metadata>
        <title>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2014"/>
        <description>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:25.497-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.815-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9830 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:42.262-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9829" version="5" class="vulnerability">
      <metadata>
        <title>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0006"/>
        <description>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.131-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9829 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:48.237-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33775"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33751"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33264"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33777"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33668"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33639"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33564"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33538"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33494"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33717"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33839"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33412"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33730"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33902"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33740"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33914"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33489"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33621"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33879"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9827" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3469"/>
        <description>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:39.932-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.090-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.859-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9827 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:30.561-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:35.064-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37045"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37456"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:36967"/>
          <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37224"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9825" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1457"/>
        <description>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.294-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9825 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:41.586-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:34.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9824" version="5" class="vulnerability">
      <metadata>
        <title>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863"/>
        <description>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:19.575-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.126-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.870-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9824 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:06.406-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:33.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34223"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34500"/>
            <criterion comment="httpd is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34481"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34166"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34468"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34603"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34461"/>
            <criterion comment="httpd is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34730"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34677"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34399"/>
            <criterion comment="httpd is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9823" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932"/>
        <description>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.198-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.833-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9823 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:52.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:33.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9821" version="5" class="vulnerability">
      <metadata>
        <title>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4683" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4683"/>
        <description>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.139-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.218-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.933-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9821 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:46.040-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:32.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9820" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:30.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.658-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9820 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:59.508-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:31.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38881"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38851"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38690"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38366"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38475"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38924"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38923"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38918"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38811"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38644"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38772"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:37948"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38947"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38194"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38876"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38504"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9819" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1689"/>
        <description>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:44.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.337-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9819 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:53.520-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:31.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9818" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312"/>
        <description>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:59.412-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.808-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9818 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:02.938-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:30.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9817" version="5" class="vulnerability">
      <metadata>
        <title>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739"/>
        <description>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.844-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.317-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9817 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:26.577-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:29.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9815" version="5" class="vulnerability">
      <metadata>
        <title>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841"/>
        <description>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.588-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:19.589-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:26.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9815 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:22.619-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:28.697-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9814" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5512"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.318-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:18.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:25.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9814 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:12.276-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:27.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9812" version="5" class="vulnerability">
      <metadata>
        <title>libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3281"/>
        <description>libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:20.837-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.819-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9812 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:01.796-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:27.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37109"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37627"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-11" test_ref="oval:org.mitre.oval:tst:37621"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:36654"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:37135"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.3" test_ref="oval:org.mitre.oval:tst:37610"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37604"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37085"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.4" test_ref="oval:org.mitre.oval:tst:37551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9811" version="5" class="vulnerability">
      <metadata>
        <title>Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0089"/>
        <description>The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:14.550-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.516-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9811 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:52.661-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:26.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31354"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31195"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31366"/>
            <criterion comment="python is earlier than 0:2.2.3-6.1" test_ref="oval:org.mitre.oval:tst:31351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30896"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:31368"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30806"/>
            <criterion comment="python is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:31194"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.1" test_ref="oval:org.mitre.oval:tst:30393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9810" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3185"/>
        <description>Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:16.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:17.233-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:24.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9810 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:38.777-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:26.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wget is earlier than 0:1.10.2-0.30E" test_ref="oval:org.mitre.oval:tst:32350"/>
            <criterion comment="curl-devel is earlier than 0:7.10.6-7.rhel3" test_ref="oval:org.mitre.oval:tst:32411"/>
            <criterion comment="curl is earlier than 0:7.10.6-7.rhel3" test_ref="oval:org.mitre.oval:tst:32351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wget is earlier than 0:1.10.2-0.40E" test_ref="oval:org.mitre.oval:tst:32340"/>
            <criterion comment="curl-devel is earlier than 0:7.12.1-6.rhel4" test_ref="oval:org.mitre.oval:tst:32364"/>
            <criterion comment="curl is earlier than 0:7.12.1-6.rhel4" test_ref="oval:org.mitre.oval:tst:32423"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9809" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3468"/>
        <description>Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.927-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:16.896-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9809 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:34.172-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:25.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9807" version="5" class="vulnerability">
      <metadata>
        <title>The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168"/>
        <description>The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:48.714-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:16.272-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9807 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:31.882-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:24.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40554"/>
            <criterion comment="perl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40615"/>
            <criterion comment="perl-CPAN is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:39713"/>
            <criterion comment="perl-CGI is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40065"/>
            <criterion comment="perl-DB_File is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40654"/>
            <criterion comment="perl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40417"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:40657"/>
            <criterion comment="perl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:39926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9806" version="5" class="vulnerability">
      <metadata>
        <title>The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2664"/>
        <description>The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:16.762-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:15.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:23.051-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9806 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:17.359-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:24.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9804" version="5" class="vulnerability">
      <metadata>
        <title>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4769"/>
        <description>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:32.588-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:15.294-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:22.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9804 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:44.458-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:23.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35948"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35993"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36045"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35949"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36098"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36066"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35942"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36105"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35835"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35597"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35261"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35907"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35319"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35123"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35894"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35781"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36109"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35308"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35856"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36044"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9803" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835"/>
        <description>Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:18.299-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:14.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:21.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9803 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:00.481-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:22.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9799" version="5" class="vulnerability">
      <metadata>
        <title>The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6116"/>
        <description>The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:19.181-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:13.793-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:20.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9799 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:16.167-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:21.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9798" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003"/>
        <description>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:38.799-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.831-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9798 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:04.189-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:20.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33447"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33884"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33550"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33984"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33936"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33976"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33799"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33867"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33958"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33791"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33929"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33764"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33070"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33716"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33788"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33928"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33930"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33951"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33950"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33932"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33656"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33963"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33466"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33846"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33660"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33687"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33689"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33499"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33719"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33811"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33258"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33567"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33738"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33938"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33663"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33066"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33875"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33789"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33829"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33434"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33704"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33790"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33886"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33982"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33715"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33856"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33815"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33470"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33864"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33546"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33718"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33954"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33629"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.13.0.1.el5" test_ref="oval:org.mitre.oval:tst:33876"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9797" version="5" class="vulnerability">
      <metadata>
        <title>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0758"/>
        <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:03.149-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.526-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9797 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:26.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:19.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31970"/>
            <criterion comment="bzip2 is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31944"/>
            <criterion comment="gzip is earlier than 0:1.3.3-12.rhel3" test_ref="oval:org.mitre.oval:tst:30880"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-11.EL3.4" test_ref="oval:org.mitre.oval:tst:31594"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bzip2-devel is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:31440"/>
            <criterion comment="bzip2 is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:31845"/>
            <criterion comment="gzip is earlier than 0:1.3.3-15.rhel4" test_ref="oval:org.mitre.oval:tst:31566"/>
            <criterion comment="bzip2-libs is earlier than 0:1.0.2-13.EL4.3" test_ref="oval:org.mitre.oval:tst:30992"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9796" version="5" class="vulnerability">
      <metadata>
        <title>Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0354"/>
        <description>Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.576-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:12.189-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:19.172-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9796 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:51.321-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:19.066-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9795" version="5" class="vulnerability">
      <metadata>
        <title>Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1056"/>
        <description>Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:14.919-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:11.764-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:18.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9795 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:01.552-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:18.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9794" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5960"/>
        <description>Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:26.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:11.231-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:18.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9794 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:19.554-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:17.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9793" version="5" class="vulnerability">
      <metadata>
        <title>The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3657"/>
        <description>The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:08.720-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:10.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:17.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9793 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:58.703-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:17.210-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9792" version="5" class="vulnerability">
      <metadata>
        <title>The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3799"/>
        <description>The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:08.940-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:10.000-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9792 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:42.907-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:16.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9791" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:18.312-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:09.523-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9791 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:09.990-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:15.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39610"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39451"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39678"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39628"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39624"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39524"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39588"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39651"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:38845"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.48.el3" test_ref="oval:org.mitre.oval:tst:39752"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39832"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39735"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39283"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39646"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39176"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-51.el4_8" test_ref="oval:org.mitre.oval:tst:39656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9790" version="5" class="vulnerability">
      <metadata>
        <title>OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245"/>
        <description>OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:04.249-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:09.245-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:16.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9790 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:45.093-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:15.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-16.50" test_ref="oval:org.mitre.oval:tst:40235"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_8.1" test_ref="oval:org.mitre.oval:tst:40149"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:39952"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40361"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-12.el5_4.6" test_ref="oval:org.mitre.oval:tst:40102"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9789" version="5" class="vulnerability">
      <metadata>
        <title>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374"/>
        <description>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:59.938-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:08.914-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:15.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9789 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:42.447-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:14.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9788" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2193"/>
        <description>Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:12.247-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:08.547-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:15.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9788 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:44.255-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:14.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="libtiff is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37555"/>
          <criterion comment="libtiff-devel is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37573"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9787" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2152" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2152"/>
        <description>Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:00.696-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:06.466-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:13.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9787 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:21.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:11.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37041"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37101"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37131"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36855"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37023"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37014"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36137"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36217"/>
            <criterion comment="openoffice.org2-draw is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37001"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36763"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36900"/>
            <criterion comment="openoffice.org2-base is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36904"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37102"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37327"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37258"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36971"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36698"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37065"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36143"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37128"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37134"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37093"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36815"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36342"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37034"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36655"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36942"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36897"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37055"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37040"/>
            <criterion comment="openoffice.org2 is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37021"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37103"/>
            <criterion comment="openoffice.org2-impress is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36121"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36947"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37015"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37052"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37077"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36551"/>
            <criterion comment="openoffice.org2-calc is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37078"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36165"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36997"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37121"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36911"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36682"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36825"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36739"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37097"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36848"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36841"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37002"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37142"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36872"/>
            <criterion comment="openoffice.org2-testtools is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37122"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:36748"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37004"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36830"/>
            <criterion comment="openoffice.org2-core is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36693"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36923"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36982"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37080"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:36346"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37019"/>
            <criterion comment="openoffice.org2-math is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37076"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37072"/>
            <criterion comment="openoffice.org2-writer is earlier than 0:2.0.4-5.7.0.5.0" test_ref="oval:org.mitre.oval:tst:37088"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37166"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37187"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37170"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37123"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37214"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37151"/>
            <criterion comment="openoffice.org is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37303"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37161"/>
            <criterion comment="openoffice.org-writer is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37011"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36920"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37334"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37136"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37183"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36862"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36809"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37264"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37095"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37090"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37053"/>
            <criterion comment="openoffice.org-javafilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37308"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37009"/>
            <criterion comment="openoffice.org-testtools is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36832"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36882"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36676"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37216"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37256"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37150"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37062"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37025"/>
            <criterion comment="openoffice.org-base is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37325"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36746"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36993"/>
            <criterion comment="openoffice.org-core is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36901"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37311"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36621"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37298"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37339"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37184"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37220"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36497"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37147"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37270"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37099"/>
            <criterion comment="openoffice.org-pyuno is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37278"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37241"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37169"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37338"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36994"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37310"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37137"/>
            <criterion comment="openoffice.org-sdk is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37110"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37194"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37221"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37030"/>
            <criterion comment="openoffice.org-draw is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37210"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37130"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37324"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37244"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37277"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37175"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36987"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36625"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36795"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37168"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37329"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37177"/>
            <criterion comment="openoffice.org-calc is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37006"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37132"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37116"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36675"/>
            <criterion comment="openoffice.org-headless is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37212"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37235"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37042"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37211"/>
            <criterion comment="openoffice.org-math is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37290"/>
            <criterion comment="openoffice.org-impress is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:36953"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:2.3.0-6.5.1.el5_2" test_ref="oval:org.mitre.oval:tst:37186"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9785" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1767"/>
        <description>Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:44.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:05.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:12.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9785 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:36.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:11.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.0.33-6" test_ref="oval:org.mitre.oval:tst:36611"/>
            <criterion comment="libxslt is earlier than 0:1.0.33-6" test_ref="oval:org.mitre.oval:tst:36656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36213"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36777"/>
            <criterion comment="libxslt is earlier than 0:1.1.11-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36639"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36716"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36669"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:36648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9784" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2704"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:54.727-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:05.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:12.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9784 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:40.755-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:10.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9783" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1111"/>
        <description>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:18.907-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:04.980-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:11.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9783 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:52.866-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:09.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cpio is earlier than 0:2.5-4.RHEL3" test_ref="oval:org.mitre.oval:tst:31643"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cpio is earlier than 0:2.5-8.RHEL4" test_ref="oval:org.mitre.oval:tst:30793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9782" version="5" class="vulnerability">
      <metadata>
        <title>The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558"/>
        <description>The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:09.833-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:04.090-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:10.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9782 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:51.507-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:08.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="evolution is earlier than 0:1.4.5-20.el3" test_ref="oval:org.mitre.oval:tst:34258"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.4" test_ref="oval:org.mitre.oval:tst:34132"/>
            <criterion comment="mutt is earlier than 5:1.4.1-5.el3" test_ref="oval:org.mitre.oval:tst:34296"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-20.el3" test_ref="oval:org.mitre.oval:tst:33933"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38549"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38591"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38694"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38715"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34331"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38864"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38837"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="evolution is earlier than 0:2.0.2-35.0.2.el4" test_ref="oval:org.mitre.oval:tst:34046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="mutt is earlier than 5:1.4.1-12.0.3.el4" test_ref="oval:org.mitre.oval:tst:34260"/>
            <criterion comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4" test_ref="oval:org.mitre.oval:tst:33955"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38523"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-35.0.2.el4" test_ref="oval:org.mitre.oval:tst:34116"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38178"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38751"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38045"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38362"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:33979"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38133"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38911"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.3.el5" test_ref="oval:org.mitre.oval:tst:33399"/>
            <criterion comment="evolution-data-server is earlier than 0:1.8.0-15.0.3.el5" test_ref="oval:org.mitre.oval:tst:34181"/>
            <criterion comment="fetchmail is earlier than 0:6.3.6-1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34122"/>
            <criterion comment="mutt is earlier than 5:1.4.2.2-3.0.2.el5" test_ref="oval:org.mitre.oval:tst:34241"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38738"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38762"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38574"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9781" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1940"/>
        <description>Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:46.501-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.782-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:10.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9781 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:08.739-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:08.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9780" version="5" class="vulnerability">
      <metadata>
        <title>The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904"/>
        <description>The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:43.418-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.393-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:09.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9780 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:16.734-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:07.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38694"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38591"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38715"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38523"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38864"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38549"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38178"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38751"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38045"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38362"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38133"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38911"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38738"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38574"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38762"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9779" version="5" class="vulnerability">
      <metadata>
        <title>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:36.944-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:03.133-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:09.462-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9779 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:29.579-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:07.383-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30638"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30381"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.4" test_ref="oval:org.mitre.oval:tst:30673"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.42" test_ref="oval:org.mitre.oval:tst:32442"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="openssl096b is earlier than 0:0.9.6b-22.42" test_ref="oval:org.mitre.oval:tst:32297"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9778" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:26.782-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:02.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:08.764-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9778 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:52.541-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:06.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9777" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:26.747-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:01.957-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:08.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9777 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:13.283-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:05.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="thunderbird is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32113"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9776" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667"/>
        <description>Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:33.447-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.716-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:07.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9776 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:22.930-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:04.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33447"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33884"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33550"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33984"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33936"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33976"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33799"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33867"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33958"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33791"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33929"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33764"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33070"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33716"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33788"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33928"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33930"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33951"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33950"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33932"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33656"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33963"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33466"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33846"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33660"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33687"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33689"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33499"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33719"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33811"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33258"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33567"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33738"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33938"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33663"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33066"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33875"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33789"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33829"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33434"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33704"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33790"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33886"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33982"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33715"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33856"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33815"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libX11-devel is earlier than 0:1.0.3-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:33685"/>
            <criterion comment="libX11 is earlier than 0:1.0.3-8.0.1.el5" test_ref="oval:org.mitre.oval:tst:33774"/>
            <criterion comment="xorg-x11-apps is earlier than 0:7.1-4.0.1.el5" test_ref="oval:org.mitre.oval:tst:33082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9775" version="5" class="vulnerability">
      <metadata>
        <title>The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4623" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4623"/>
        <description>The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:11.650-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.430-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.963-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9775 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:37.386-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:03.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9774" version="5" class="vulnerability">
      <metadata>
        <title>The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2874"/>
        <description>The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:32.581-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:00.224-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9774 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:45.009-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:03.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31989"/>
          <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31269"/>
          <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.8" test_ref="oval:org.mitre.oval:tst:31920"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9772" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6112"/>
        <description>Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:53.239-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:59.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:06.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9772 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:18.357-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:02.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9771" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798"/>
        <description>Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:02.322-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:59.337-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:05.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9771 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:12.545-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:02.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-12.el4" test_ref="oval:org.mitre.oval:tst:34426"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-12.el4" test_ref="oval:org.mitre.oval:tst:34317"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-12.el4" test_ref="oval:org.mitre.oval:tst:33439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-18.el5" test_ref="oval:org.mitre.oval:tst:34286"/>
            <criterion comment="libpcap-devel is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34191"/>
            <criterion comment="libpcap is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34045"/>
            <criterion comment="tcpdump is earlier than 14:3.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:33937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9770" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0504"/>
        <description>Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:08.343-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:58.859-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:05.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9770 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:31.525-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:01.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9768" version="5" class="vulnerability">
      <metadata>
        <title>The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs.  NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2784"/>
        <description>The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs.  NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:05.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:57.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:04.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9768 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:42.335-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:00.550-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9767" version="5" class="vulnerability">
      <metadata>
        <title>FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1807"/>
        <description>FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:05.197-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:57.656-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:04.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9767 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:35.880-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:22:00.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36608"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36928"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36978"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37295"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36877"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37292"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37321"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37312"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37160"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9766" version="5" class="vulnerability">
      <metadata>
        <title>The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848"/>
        <description>The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:30.668-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:03.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9766 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:29.189-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38255"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38332"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39122"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39058"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39247"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39145"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38795"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38831"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38585"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39130"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:38567"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.el5" test_ref="oval:org.mitre.oval:tst:39245"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9765" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5456"/>
        <description>Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:25.674-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.647-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:03.132-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9765 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:32.791-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33189"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33318"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33102"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33080"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33269"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33326"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32926"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32622"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9764" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2379"/>
        <description>Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:46.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:56.387-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:02.813-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9764 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:30.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:58.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-8.el3" test_ref="oval:org.mitre.oval:tst:38111"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" test_ref="oval:org.mitre.oval:tst:37956"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:37617"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9763" version="5" class="vulnerability">
      <metadata>
        <title>The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3511"/>
        <description>The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:36.301-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:55.813-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:02.280-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9763 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:27.518-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:57.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9762" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested option tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2779"/>
        <description>Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested &lt;option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:18.092-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:55.326-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:01.673-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9762 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:45.580-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:56.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9761" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2315"/>
        <description>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:07.718-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.865-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:01.270-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9761 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:14.460-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:56.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9760" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3191"/>
        <description>Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:01.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9760 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:00.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:55.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32490"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32463"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:31538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:31551"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.3" test_ref="oval:org.mitre.oval:tst:32230"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32368"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32431"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9759" version="5" class="vulnerability">
      <metadata>
        <title>The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0731"/>
        <description>The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:21.585-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:54.175-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9759 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:00.174-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:55.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_8.7" test_ref="oval:org.mitre.oval:tst:39971"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_8.7" test_ref="oval:org.mitre.oval:tst:40233"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9758" version="5" class="vulnerability">
      <metadata>
        <title>smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452"/>
        <description>smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:19.184-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:53.784-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:00.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9758 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:22.985-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:54.520-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33498"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:32942"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33319"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.12" test_ref="oval:org.mitre.oval:tst:33433"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:32739"/>
            <criterion comment="samba-swat is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33281"/>
            <criterion comment="samba-client is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33449"/>
            <criterion comment="samba is earlier than 0:3.0.10-1.4E.11" test_ref="oval:org.mitre.oval:tst:33469"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33413"/>
            <criterion comment="samba-swat is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33148"/>
            <criterion comment="samba-client is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33443"/>
            <criterion comment="samba is earlier than 0:3.0.23c-2.el5.2" test_ref="oval:org.mitre.oval:tst:33362"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9756" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4624"/>
        <description>CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:45.170-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:53.293-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:59.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9756 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:25.598-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:53.750-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.6" test_ref="oval:org.mitre.oval:tst:34946"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9753" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3809"/>
        <description>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:19.804-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:52.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:58.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9753 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:41.076-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:52.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9750" version="5" class="vulnerability">
      <metadata>
        <title>wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1488"/>
        <description>wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:41.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:51.361-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:57.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9750 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:05.438-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:51.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9749" version="5" class="vulnerability">
      <metadata>
        <title>A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0994"/>
        <description>A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:21.470-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.758-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9749 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:24.543-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:50.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9748" version="5" class="vulnerability">
      <metadata>
        <title>The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3276" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3276"/>
        <description>The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:10.717-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.364-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.491-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9748 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:29.513-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:49.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32345"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32444"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32109"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32476"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32343"/>
            <criterion comment="kernel is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:31877"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32362"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:32190"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-40.EL" test_ref="oval:org.mitre.oval:tst:31899"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9747" version="5" class="vulnerability">
      <metadata>
        <title>Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0109"/>
        <description>Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:12.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:50.003-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:56.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9747 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:01.374-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:49.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32376"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32370"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32357"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.22.4" test_ref="oval:org.mitre.oval:tst:32193"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31576"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31826"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:32196"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.4" test_ref="oval:org.mitre.oval:tst:32241"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9746" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6501"/>
        <description>Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:14.895-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:49.515-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:55.625-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9746 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:06.247-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:48.711-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9743" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183"/>
        <description>Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:57.439-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:54.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9743 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:01.351-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:47.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:31219"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:30876"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:31174"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:30884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9741" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2027"/>
        <description>Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:41.854-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:48.236-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:54.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9741 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:45.868-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:46.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.9.2-4.el4_8.1" test_ref="oval:org.mitre.oval:tst:39356"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.11.1-6.el5_4.1" test_ref="oval:org.mitre.oval:tst:39490"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9740" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that tragger an assertion error related to unexpected length values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4574"/>
        <description>Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that tragger an assertion error related to unexpected length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.865-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:47.739-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:53.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9740 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:49.858-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:46.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9739" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555"/>
        <description>PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:22.918-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:47.130-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:52.923-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9739 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:48.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:45.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33558"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33220"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33285"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33432"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33464"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33104"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33317"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33537"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33539"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33243"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33246"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33442"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33531"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33065"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32982"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33144"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33007"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33534"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33427"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33173"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33069"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33496"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33181"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33488"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33593"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33121"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33568"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33396"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33603"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32610"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32997"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33536"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9735" version="5" class="vulnerability">
      <metadata>
        <title>The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4573"/>
        <description>The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:46.151-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:45.691-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:51.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9735 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:32.084-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:43.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:34612"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35360"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35290"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35242"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35278"/>
            <criterion comment="kernel is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35340"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:34986"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35236"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-52.EL" test_ref="oval:org.mitre.oval:tst:35318"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35329"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35328"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35371"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35052"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:34704"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35333"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:34761"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35265"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.9.EL" test_ref="oval:org.mitre.oval:tst:35040"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35220"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35380"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34544"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35347"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35287"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34472"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35307"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34914"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35213"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:34797"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.14.el5" test_ref="oval:org.mitre.oval:tst:35297"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9734" version="5" class="vulnerability">
      <metadata>
        <title>The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726"/>
        <description>The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:40.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:45.206-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:50.917-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9734 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:23.267-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:42.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40810"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40798"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40737"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40705"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40784"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40711"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40801"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40491"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40523"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40665"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40648"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9732" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0744"/>
        <description>Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:20.574-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:44.552-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:50.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9732 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:43.565-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:42.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
            <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9730" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0981"/>
        <description>Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:27.304-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:43.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:49.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9730 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:38.157-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:41.312-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9728" version="5" class="vulnerability">
      <metadata>
        <title>The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3475"/>
        <description>The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:04.145-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.867-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:48.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9728 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:46.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:40.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9727" version="5" class="vulnerability">
      <metadata>
        <title>The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3857"/>
        <description>The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:13.802-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.478-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:48.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9727 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:01.558-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:40.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9726" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6115"/>
        <description>Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:43.583-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:42.112-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:47.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9726 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:35.429-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:39.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9725" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1659"/>
        <description>Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:22.361-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:41.834-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:47.524-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9725 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:28.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:39.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35615"/>
            <criterion comment="pcre is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35501"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:6.6-2.el5_0.1" test_ref="oval:org.mitre.oval:tst:35420"/>
            <criterion comment="pcre is earlier than 0:6.6-2.el5_0.1" test_ref="oval:org.mitre.oval:tst:35187"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9724" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658"/>
        <description>Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:05.665-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:41.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:46.762-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9724 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:46.798-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:38.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9723" version="6" class="vulnerability">
      <metadata>
        <title>The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstated by the (1) /admin?OP=redirectURL=% and (2) /admin?URL=/admin/OP=% URIs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748"/>
        <description>The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:34.305-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:40.724-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:46.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9723 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:55.637-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:37.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40547"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40758"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.65" test_ref="oval:org.mitre.oval:tst:40348"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40606"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40609"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.6" test_ref="oval:org.mitre.oval:tst:40697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40805"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40819"/>
            <criterion comment="cups is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40803"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-18.el5_5.4" test_ref="oval:org.mitre.oval:tst:40393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9722" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0909"/>
        <description>Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:01.285-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:39.971-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:45.626-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9722 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:20.800-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:36.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9720" version="5" class="vulnerability">
      <metadata>
        <title>The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0442"/>
        <description>The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:29.228-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:39.164-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:44.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9720 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:59.782-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:35.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40180"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40440"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40426"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40220"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39618"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40140"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40502"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39925"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40137"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40551"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40486"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40521"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40292"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40516"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40066"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40399"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40512"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40314"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40428"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40366"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40401"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40402"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40538"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:39839"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40515"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40505"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40251"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40253"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40509"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9719" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7234"/>
        <description>Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:11.863-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.830-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:44.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9719 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:48.421-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:34.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.3" test_ref="oval:org.mitre.oval:tst:37424"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" test_ref="oval:org.mitre.oval:tst:37925"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9717" version="5" class="vulnerability">
      <metadata>
        <title>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:54.951-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:38.343-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:43.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9717 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:48.765-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:34.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31991"/>
          <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31339"/>
          <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31258"/>
          <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:32054"/>
          <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.9" test_ref="oval:org.mitre.oval:tst:31494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9715" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437"/>
        <description>Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:31.740-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:37.468-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:43.062-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9715 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:01.969-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:33.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40810"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40798"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40737"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40705"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40784"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40711"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40801"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40491"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40523"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40665"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40648"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9714" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888"/>
        <description>Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:38.808-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:37.126-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9714 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:10.645-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31559"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31693"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31615"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:30852"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31603"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:31062"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31685"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.3" test_ref="oval:org.mitre.oval:tst:31089"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.7" test_ref="oval:org.mitre.oval:tst:31747"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.16" test_ref="oval:org.mitre.oval:tst:30949"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31263"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31323"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9713" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1462"/>
        <description>Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:39.744-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.823-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9713 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:19.469-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.415-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9712" version="5" class="vulnerability">
      <metadata>
        <title>Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2929"/>
        <description>Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.606-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:42.195-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9712 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:50.785-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:32.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.2" test_ref="oval:org.mitre.oval:tst:32358"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2" test_ref="oval:org.mitre.oval:tst:32237"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9711" version="5" class="vulnerability">
      <metadata>
        <title>Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2479" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2479"/>
        <description>Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:33.643-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.391-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9711 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:52.444-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:31.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.14" test_ref="oval:org.mitre.oval:tst:32129"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.11" test_ref="oval:org.mitre.oval:tst:32053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9710" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0891"/>
        <description>Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:45.459-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:36.080-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9710 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:26.457-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:31.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31425"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-15" test_ref="oval:org.mitre.oval:tst:31683"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31384"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" test_ref="oval:org.mitre.oval:tst:31449"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-15" test_ref="oval:org.mitre.oval:tst:31230"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" test_ref="oval:org.mitre.oval:tst:31640"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-14" test_ref="oval:org.mitre.oval:tst:31176"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" test_ref="oval:org.mitre.oval:tst:31509"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-14" test_ref="oval:org.mitre.oval:tst:31725"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9709" version="5" class="vulnerability">
      <metadata>
        <title>VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0001"/>
        <description>VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:01.857-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:35.534-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:41.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9709 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:32.989-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:30.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9708" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469"/>
        <description>Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:10.721-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:35.173-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:40.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9708 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:27.634-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:29.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31573"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31050"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31373"/>
            <criterion comment="telnet is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31054"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31472"/>
            <criterion comment="telnet-server is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31463"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31015"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31409"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:30952"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31575"/>
            <criterion comment="telnet is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31498"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31481"/>
            <criterion comment="telnet-server is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31275"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31526"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9704" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3117"/>
        <description>Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:37.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:34.169-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:39.624-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9704 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:56.365-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:27.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32211"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32773"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32763"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32657"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32835"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9703" version="5" class="vulnerability">
      <metadata>
        <title>The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2778"/>
        <description>The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:36.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:33.618-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:39.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9703 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:20.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:27.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9702" version="5" class="vulnerability">
      <metadata>
        <title>drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538"/>
        <description>drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:21.466-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:33.137-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:38.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9702 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:11.436-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:26.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39702"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39797"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39763"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39709"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39503"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39617"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39773"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39516"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39093"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39662"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39645"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39650"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39813"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39095"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39770"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39099"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39700"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39408"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39590"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39719"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39789"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:38905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9700" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1456"/>
        <description>Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:54.326-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:32.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:38.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9700 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:40.455-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:26.252-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9697" version="5" class="vulnerability">
      <metadata>
        <title>io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2975"/>
        <description>io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:48.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:31.892-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:37.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9697 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:28.518-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:25.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32203"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32214"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32393"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32388"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32239"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32313"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32331"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9696" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1990"/>
        <description>Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:24.929-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:31.439-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:36.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9696 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:26.280-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:24.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32694"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32635"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32094"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32734"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32506"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32594"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-33.ent" test_ref="oval:org.mitre.oval:tst:32698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32619"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32609"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:31938"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:31791"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32729"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32676"/>
            <criterion comment="php is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32607"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32412"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32084"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32271"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32269"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32783"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32718"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.15" test_ref="oval:org.mitre.oval:tst:32732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9690" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3388"/>
        <description>Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:26.464-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.680-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:35.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9690 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:42.573-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:22.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34378"/>
            <criterion comment="qt is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34752"/>
            <criterion comment="qt-devel is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34863"/>
            <criterion comment="qt-MySQL is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34860"/>
            <criterion comment="qt-ODBC is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34610"/>
            <criterion comment="qt-designer is earlier than 1:3.1.2-16.RHEL3" test_ref="oval:org.mitre.oval:tst:34657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34716"/>
            <criterion comment="qt is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34773"/>
            <criterion comment="qt-devel is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34824"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34273"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34815"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:33935"/>
            <criterion comment="qt-designer is earlier than 1:3.3.3-11.RHEL4" test_ref="oval:org.mitre.oval:tst:34901"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34546"/>
            <criterion comment="qt is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34540"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34891"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34751"/>
            <criterion comment="qt-designer is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34786"/>
            <criterion comment="qt-devel is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34503"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34497"/>
            <criterion comment="qt-devel-docs is earlier than 1:3.3.6-21.el5" test_ref="oval:org.mitre.oval:tst:34823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9689" version="5" class="vulnerability">
      <metadata>
        <title>login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7108"/>
        <description>login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:33.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.498-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.818-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9689 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:47.286-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:22.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="util-linux is earlier than 0:2.12a-16.EL4.25" test_ref="oval:org.mitre.oval:tst:34034"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9688" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0753"/>
        <description>Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:11.791-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:29.279-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.585-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9688 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:22.145-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:21.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cvs is earlier than 0:1.11.2-27" test_ref="oval:org.mitre.oval:tst:31763"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cvs is earlier than 0:1.11.17-7.RHEL4" test_ref="oval:org.mitre.oval:tst:31635"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9687" version="5" class="vulnerability">
      <metadata>
        <title>The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0739"/>
        <description>The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.277-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.974-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:34.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9687 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:24.517-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:21.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31514"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31448"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31593"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31548"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9686" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654"/>
        <description>Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:12.365-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.445-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:33.753-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9686 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:11.611-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:20.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39378"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39359"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39036"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39270"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39397"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39118"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38466"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39081"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:38976"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39181"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39364"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39293"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9685" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6451"/>
        <description>Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:39.866-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:28.073-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:33.379-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9685 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:17.088-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:20.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9683" version="5" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:48.539-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:26.928-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:32.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9683 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:34.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:19.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9682" version="5" class="vulnerability">
      <metadata>
        <title>Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3656"/>
        <description>Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:24.344-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:26.534-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:31.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9682 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:09.087-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:18.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9681" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775"/>
        <description>Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:29.793-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:25.977-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:31.332-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9681 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:02.799-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:17.908-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9679" version="5" class="vulnerability">
      <metadata>
        <title>The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4058"/>
        <description>The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:10.182-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:25.190-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:30.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9679 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:10.432-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:16.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9678" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4585"/>
        <description>Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:30.846-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.897-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:30.217-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9678 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:00.352-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:16.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32303"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32466"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32538"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9677" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0599"/>
        <description>Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:28.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.609-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:29.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9677 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:13.623-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:15.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9675" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0411"/>
        <description>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:46.188-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:24.084-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:29.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9675 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:40.678-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:15.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40200"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40276"/>
            <criterion comment="systemtap is earlier than 0:0.6.2-2.el4_8.1" test_ref="oval:org.mitre.oval:tst:40274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-initscript is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39973"/>
            <criterion comment="systemtap-runtime is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39856"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:40046"/>
            <criterion comment="systemtap-client is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:40146"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39433"/>
            <criterion comment="systemtap is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39868"/>
            <criterion comment="systemtap-server is earlier than 0:0.9.7-5.el5_4.3" test_ref="oval:org.mitre.oval:tst:39484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9674" version="5" class="vulnerability">
      <metadata>
        <title>sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0557"/>
        <description>sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:19.826-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:23.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:28.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9674 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:53.514-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:14.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30189"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30542"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30504"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30169"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29589"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29669"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30299"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30268"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9670" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3843"/>
        <description>The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:59.672-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:22.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:27.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9670 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:54.102-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:13.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9669" version="5" class="vulnerability">
      <metadata>
        <title>The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2496" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2496"/>
        <description>The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:24.524-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:22.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:27.453-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9669 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:44.898-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:13.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-4.EL4.1" test_ref="oval:org.mitre.oval:tst:32391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9668" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2808"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:55.758-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:21.688-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:26.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9668 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:04.977-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:12.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9667" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498"/>
        <description>Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:47.545-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.943-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.995-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9667 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:16.534-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:11.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9666" version="5" class="vulnerability">
      <metadata>
        <title>The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3641"/>
        <description>The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:34.316-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.603-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9666 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:07.539-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:10.865-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37294"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37772"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37394"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37546"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37714"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37215"/>
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37378"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37794"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37702"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9665" version="5" class="vulnerability">
      <metadata>
        <title>The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3244"/>
        <description>The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:40.827-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.362-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9665 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:12.804-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:10.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9664" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905"/>
        <description>Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:35.218-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:20.074-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:25.053-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9664 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:04.811-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:09.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:39137"/>
            <criterion comment="newt is earlier than 0:0.51.5-2.el3" test_ref="oval:org.mitre.oval:tst:39439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:39340"/>
            <criterion comment="newt is earlier than 0:0.51.6-10.el4_8.1" test_ref="oval:org.mitre.oval:tst:39343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="newt-devel is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:39387"/>
            <criterion comment="newt is earlier than 0:0.52.2-12.el5_4.1" test_ref="oval:org.mitre.oval:tst:38962"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9662" version="5" class="vulnerability">
      <metadata>
        <title>The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5510"/>
        <description>The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:43.646-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:19.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:24.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9662 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:27.567-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:09.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9661" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4262"/>
        <description>Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:21.720-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:19.213-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:24.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9661 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:35.114-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:08.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9660" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5013"/>
        <description>Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:29.645-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.715-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9660 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:08.551-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:08.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9659" version="5" class="vulnerability">
      <metadata>
        <title>fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4348"/>
        <description>fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:40.544-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9659 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:10.193-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:07.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.3" test_ref="oval:org.mitre.oval:tst:33046"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.el4.5" test_ref="oval:org.mitre.oval:tst:33350"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9658" version="5" class="vulnerability">
      <metadata>
        <title>The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184"/>
        <description>The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:18.437-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.349-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:23.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9658 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:46.788-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:07.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.4" test_ref="oval:org.mitre.oval:tst:30796"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-28.3" test_ref="oval:org.mitre.oval:tst:31274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9657" version="5" class="vulnerability">
      <metadata>
        <title>Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0967"/>
        <description>Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:58.882-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:18.132-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:22.969-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9657 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:50.647-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:06.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el3" test_ref="oval:org.mitre.oval:tst:31686"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el4" test_ref="oval:org.mitre.oval:tst:31403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9656" version="5" class="vulnerability">
      <metadata>
        <title>Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4988"/>
        <description>Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:23.974-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:17.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:22.353-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9656 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:53.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:06.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9654" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1467" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1467"/>
        <description>Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:39.939-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:16.840-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.722-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9654 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:37.931-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:05.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9653" version="5" class="vulnerability">
      <metadata>
        <title>The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3183"/>
        <description>The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:13.552-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:16.636-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:21.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9653 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:58.745-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:05.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="w3c-libwww-devel is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:33967"/>
          <criterion comment="w3c-libwww is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:34049"/>
          <criterion comment="w3c-libwww-apps is earlier than 0:5.4.0-10.1.RHEL4.2" test_ref="oval:org.mitre.oval:tst:34020"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9651" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1237"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:55.698-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:15.889-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:20.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9651 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:22.592-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:04.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9650" version="5" class="vulnerability">
      <metadata>
        <title>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401"/>
        <description>FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:22.001-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:15.384-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:20.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9650 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:45.764-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:03.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="firefox is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31302"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9648" version="5" class="vulnerability">
      <metadata>
        <title>The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814"/>
        <description>The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:22.505-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:14.645-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:19.433-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9648 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:07.524-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:02.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9646" version="5" class="vulnerability">
      <metadata>
        <title>The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2664"/>
        <description>The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:29.319-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:13.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:18.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9646 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:37.324-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:01.366-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9645" version="5" class="vulnerability">
      <metadata>
        <title>Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165"/>
        <description>Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:33.502-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:13.548-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:18.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9645 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:31.530-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:21:00.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31113"/>
            <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.8" test_ref="oval:org.mitre.oval:tst:31092"/>
            <criterion comment="kdelibs is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30244"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.9" test_ref="oval:org.mitre.oval:tst:30826"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31221"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:30975"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9643" version="5" class="vulnerability">
      <metadata>
        <title>The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3835"/>
        <description>The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:58.351-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:12.714-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:17.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9643 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:23.890-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:59.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9642" version="5" class="vulnerability">
      <metadata>
        <title>nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5021"/>
        <description>nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:55.209-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:12.109-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:16.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9642 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:22.254-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:58.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9641" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274"/>
        <description>Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:58.227-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:11.501-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:16.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9641 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:12.067-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:58.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9640" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468"/>
        <description>Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:52.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:11.141-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:15.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9640 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:34.936-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:57.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31573"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31050"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31373"/>
            <criterion comment="telnet is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31054"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31472"/>
            <criterion comment="telnet-server is earlier than 1:0.17-26.EL3.2" test_ref="oval:org.mitre.oval:tst:31463"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-42" test_ref="oval:org.mitre.oval:tst:31015"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31409"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:30952"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31575"/>
            <criterion comment="telnet is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31498"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31481"/>
            <criterion comment="telnet-server is earlier than 1:0.17-31.EL4.2" test_ref="oval:org.mitre.oval:tst:31275"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-12" test_ref="oval:org.mitre.oval:tst:31526"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9639" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1751"/>
        <description>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:12.818-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:10.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:15.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9639 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:47.453-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:56.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31903"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31997"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32058"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32011"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31769"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31610"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31993"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31996"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32047"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31303"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31718"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31829"/>
            <criterion comment="php is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31181"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32064"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31623"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31882"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31988"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32010"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31662"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31873"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9638" version="5" class="vulnerability">
      <metadata>
        <title>The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2098"/>
        <description>The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:06.868-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:10.370-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.983-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9638 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:33.919-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:56.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9637" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4566"/>
        <description>Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:17.073-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:09.831-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9637 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:15.289-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:55.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9636" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file.  NOTE: this issue is due to an incomplete fix for CVE-2004-0888.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1374"/>
        <description>Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file.  NOTE: this issue is due to an incomplete fix for CVE-2004-0888.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:28.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:09.568-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:14.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9636 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:58.347-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:55.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36146"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36214"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36474"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:35913"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36036"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9635" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1951" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1951"/>
        <description>Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:25.732-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:08.533-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:13.150-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9635 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:29.302-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:54.200-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.13-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36852"/>
            <criterion comment="sblim-cmpi-params is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36779"/>
            <criterion comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.13-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36564"/>
            <criterion comment="sblim-cmpi-devel is earlier than 0:1.0.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36536"/>
            <criterion comment="sblim-wbemcli is earlier than 0:1.5.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36791"/>
            <criterion comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.11-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36824"/>
            <criterion comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36765"/>
            <criterion comment="sblim-cmpi-network is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36588"/>
            <criterion comment="sblim-cmpi-syslog is earlier than 0:0.7.9-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36247"/>
            <criterion comment="sblim-cmpi-syslog-test is earlier than 0:0.7.9-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36076"/>
            <criterion comment="sblim-cmpi-fsvol is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36660"/>
            <criterion comment="sblim-gather-devel is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36712"/>
            <criterion comment="sblim-cmpi-network-test is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36650"/>
            <criterion comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.3-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36717"/>
            <criterion comment="sblim-cmpi-network-devel is earlier than 0:1.3.7-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36209"/>
            <criterion comment="sblim-gather-test is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36775"/>
            <criterion comment="sblim-cmpi-base is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36759"/>
            <criterion comment="sblim-gather-provider is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36250"/>
            <criterion comment="sblim-cmpi-params-test is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36849"/>
            <criterion comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.11-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36095"/>
            <criterion comment="sblim-cmpi-sysfs is earlier than 0:1.1.8-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36718"/>
            <criterion comment="sblim-cmpi-base-test is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36724"/>
            <criterion comment="sblim-cmpi-base-devel is earlier than 0:1.5.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36680"/>
            <criterion comment="sblim is earlier than 0:1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36800"/>
            <criterion comment="sblim-testsuite is earlier than 0:1.2.4-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36753"/>
            <criterion comment="sblim-gather is earlier than 0:2.1.1-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36780"/>
            <criterion comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.8-13a.el4_6.1" test_ref="oval:org.mitre.oval:tst:36842"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sblim-cim-client-javadoc is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36701"/>
            <criterion comment="sblim-wbemcli is earlier than 0:1.5.1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36793"/>
            <criterion comment="sblim-cmpi-samba-test is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36850"/>
            <criterion comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.12-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36447"/>
            <criterion comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36689"/>
            <criterion comment="sblim-cmpi-syslog is earlier than 0:0.7.11-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36783"/>
            <criterion comment="sblim-cmpi-fsvol is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36787"/>
            <criterion comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36899"/>
            <criterion comment="sblim-gather-test is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35986"/>
            <criterion comment="sblim-gather-provider is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36687"/>
            <criterion comment="sblim-cmpi-params-test is earlier than 0:1.2.6-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36673"/>
            <criterion comment="sblim-cmpi-dns is earlier than 0:0.5.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36001"/>
            <criterion comment="sblim-cmpi-dns-test is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36196"/>
            <criterion comment="sblim-cmpi-samba-devel is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36797"/>
            <criterion comment="sblim-cmpi-dns-devel is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36692"/>
            <criterion comment="sblim-testsuite is earlier than 0:1.2.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36633"/>
            <criterion comment="sblim-gather is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36802"/>
            <criterion comment="sblim-tools-libra is earlier than 0:0.2.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36489"/>
            <criterion comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.14-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36714"/>
            <criterion comment="sblim-cmpi-devel is earlier than 0:1.0.4-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36888"/>
            <criterion comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.14-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36479"/>
            <criterion comment="sblim-cmpi-params is earlier than 0:1.2.6-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36857"/>
            <criterion comment="sblim-tools-libra-devel is earlier than 0:0.2.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36970"/>
            <criterion comment="sblim-cmpi-network is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36578"/>
            <criterion comment="sblim-cmpi-syslog-test is earlier than 0:0.7.11-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35968"/>
            <criterion comment="sblim-cmpi-network-test is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36896"/>
            <criterion comment="sblim-gather-devel is earlier than 0:2.1.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36721"/>
            <criterion comment="sblim-cmpi-network-devel is earlier than 0:1.3.8-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36890"/>
            <criterion comment="sblim-cmpi-base is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36892"/>
            <criterion comment="sblim-cim-client is earlier than 0:1.3.3-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36709"/>
            <criterion comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.12-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36856"/>
            <criterion comment="sblim-cim-client-manual is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36889"/>
            <criterion comment="sblim-cmpi-sysfs is earlier than 0:1.1.9-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35937"/>
            <criterion comment="sblim-cmpi-base-test is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36354"/>
            <criterion comment="sblim-cmpi-samba is earlier than 0:0.5.2-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:35992"/>
            <criterion comment="sblim is earlier than 0:1-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36245"/>
            <criterion comment="sblim-cmpi-base-devel is earlier than 0:1.5.5-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36624"/>
            <criterion comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.9-31.el5_2.1" test_ref="oval:org.mitre.oval:tst:36863"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9634" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159"/>
        <description>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:50.551-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:08.263-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:12.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9634 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:38.616-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:53.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.1.2-6.el3" test_ref="oval:org.mitre.oval:tst:39300"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:38589"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" test_ref="oval:org.mitre.oval:tst:38719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9633" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0148"/>
        <description>Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:48.722-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:07.962-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:12.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9633 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:30.994-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:53.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="cscope is earlier than 0:15.5-15.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9632" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146"/>
        <description>Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:58.393-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:07.366-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:11.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9632 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:15.795-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:52.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9631" version="5" class="vulnerability">
      <metadata>
        <title>The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0949"/>
        <description>The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:10.975-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.986-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:11.407-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9631 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:49.651-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:51.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38765"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:37797"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38351"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38503"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38748"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38713"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38764"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38681"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" test_ref="oval:org.mitre.oval:tst:38653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9630" version="5" class="vulnerability">
      <metadata>
        <title>net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007"/>
        <description>net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:12.864-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.379-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.854-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9630 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:47.681-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:51.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40241"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40097"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40139"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40308"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40210"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40082"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40354"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40326"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39940"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39363"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40228"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40098"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40231"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39918"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39938"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40088"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40237"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39997"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40240"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40352"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39930"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40055"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9629" version="5" class="vulnerability">
      <metadata>
        <title>The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-6472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6472"/>
        <description>The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:57.215-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:06.089-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.553-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9629 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:54.445-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:50.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9628" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2114"/>
        <description>Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:45.537-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:05.549-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:10.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9628 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:17.225-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:49.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9627" version="5" class="vulnerability">
      <metadata>
        <title>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:23.903-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.970-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:09.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9627 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:41.687-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:49.236-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37016"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37047"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:36733"/>
            <criterion comment="bind is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:36959"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-22.el3" test_ref="oval:org.mitre.oval:tst:37048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36719"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36575"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:37082"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:36876"/>
            <criterion comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" test_ref="oval:org.mitre.oval:tst:37007"/>
            <criterion comment="bind is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36100"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-28.0.1.el4" test_ref="oval:org.mitre.oval:tst:36925"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37003"/>
            <criterion comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37017"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36924"/>
            <criterion comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:37069"/>
            <criterion comment="dnsmasq is earlier than 0:2.45-1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37588"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36601"/>
            <criterion comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36960"/>
            <criterion comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36962"/>
            <criterion comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36667"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:36806"/>
            <criterion comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36092"/>
            <criterion comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" test_ref="oval:org.mitre.oval:tst:37038"/>
            <criterion comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36853"/>
            <criterion comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" test_ref="oval:org.mitre.oval:tst:36790"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9626" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6502" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6502"/>
        <description>Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:40.379-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:04.480-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9626 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:02.219-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:48.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9623" version="5" class="vulnerability">
      <metadata>
        <title>BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4096"/>
        <description>BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:55.413-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:03.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:08.164-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9623 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:09.956-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:46.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30151"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30374"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30138"/>
            <criterion comment="bind is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:29802"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-14_EL3" test_ref="oval:org.mitre.oval:tst:30540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30310"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30454"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30510"/>
            <criterion comment="bind is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30416"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-16.EL4" test_ref="oval:org.mitre.oval:tst:30409"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9622" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5340"/>
        <description>Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:56.515-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:03.196-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:07.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9622 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:37.498-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:46.115-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9620" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3933"/>
        <description>Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.000-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:02.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9620 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:00.406-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:45.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9619" version="5" class="vulnerability">
      <metadata>
        <title>Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547"/>
        <description>Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:31.976-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:01.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9619 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:37.893-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:45.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38140"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38464"/>
            <criterion comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38477"/>
            <criterion comment="evolution is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38489"/>
            <criterion comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38193"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:38514"/>
            <criterion comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37983"/>
            <criterion comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37891"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9618" version="5" class="vulnerability">
      <metadata>
        <title>slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4600" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4600"/>
        <description>slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:53.371-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:01.349-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:06.164-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9618 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:57.699-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:44.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openldap-devel is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34514"/>
            <criterion comment="openldap-clients is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34458"/>
            <criterion comment="openldap is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:34561"/>
            <criterion comment="openldap-servers is earlier than 0:2.0.27-23" test_ref="oval:org.mitre.oval:tst:33949"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-7.4E" test_ref="oval:org.mitre.oval:tst:33968"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34054"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34115"/>
            <criterion comment="openldap is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34114"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:34101"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-7.4E" test_ref="oval:org.mitre.oval:tst:33882"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9617" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3619"/>
        <description>Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:09.813-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:00.682-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:05.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9617 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:50.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:43.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34573"/>
            <criterion comment="gcc-java is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34533"/>
            <criterion comment="gcc-g77 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34680"/>
            <criterion comment="libgcj is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34364"/>
            <criterion comment="gcc-c++ is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34558"/>
            <criterion comment="libobjc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34188"/>
            <criterion comment="libstdc++ is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34631"/>
            <criterion comment="libf2c is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34315"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34518"/>
            <criterion comment="gcc-objc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34287"/>
            <criterion comment="libgnat is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34120"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34471"/>
            <criterion comment="gcc-gnat is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34329"/>
            <criterion comment="cpp is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34617"/>
            <criterion comment="libgcj-devel is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:33808"/>
            <criterion comment="gcc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:34691"/>
            <criterion comment="libgcc is earlier than 0:3.2.3-59" test_ref="oval:org.mitre.oval:tst:33732"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33781"/>
            <criterion comment="gcc-java is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33255"/>
            <criterion comment="gcc-g77 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33431"/>
            <criterion comment="libgcj is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33641"/>
            <criterion comment="gcc-c++ is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33545"/>
            <criterion comment="libobjc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33752"/>
            <criterion comment="libstdc++ is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34001"/>
            <criterion comment="libf2c is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33787"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34089"/>
            <criterion comment="gcc-objc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33916"/>
            <criterion comment="libgnat is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33942"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:33437"/>
            <criterion comment="gcc-gnat is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34105"/>
            <criterion comment="cpp is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34086"/>
            <criterion comment="libgcj-devel is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34100"/>
            <criterion comment="gcc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34111"/>
            <criterion comment="libgcc is earlier than 0:3.4.6-8" test_ref="oval:org.mitre.oval:tst:34014"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9616" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0102"/>
        <description>Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:08.344-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:00.432-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:05.220-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9616 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:56.892-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:43.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-14" test_ref="oval:org.mitre.oval:tst:31420"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-14" test_ref="oval:org.mitre.oval:tst:30692"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:2.0.2-16" test_ref="oval:org.mitre.oval:tst:31620"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-16" test_ref="oval:org.mitre.oval:tst:31842"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9615" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:49.534-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:59.608-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:04.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9615 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:15.413-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:42.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31985"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31627"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31972"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31705"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31773"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31675"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:32017"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31942"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31963"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31156"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31905"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31784"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31310"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31908"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31949"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31827"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31806"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31649"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31020"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31743"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31721"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31883"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31764"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31959"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31843"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31616"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31732"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31371"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-95.EL" test_ref="oval:org.mitre.oval:tst:31803"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31419"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31188"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31835"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31397"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:30870"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31767"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31614"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31663"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31651"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31689"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31765"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31036"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:30807"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31179"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31491"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31427"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31761"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" test_ref="oval:org.mitre.oval:tst:31667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9613" version="5" class="vulnerability">
      <metadata>
        <title>unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0990"/>
        <description>unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:22.778-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:59.101-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:03.826-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9613 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:19.894-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:41.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-16.2" test_ref="oval:org.mitre.oval:tst:31587"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-22.2" test_ref="oval:org.mitre.oval:tst:31528"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9611" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3802"/>
        <description>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:41.250-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.979-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:02.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9611 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:40.461-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:40.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9610" version="5" class="vulnerability">
      <metadata>
        <title>SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1454" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1454"/>
        <description>SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:11.283-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:02.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9610 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:19.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:39.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" test_ref="oval:org.mitre.oval:tst:31698"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:32002"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31962"/>
            <criterion comment="freeradius is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31992"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9609" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772"/>
        <description>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:20.634-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:57.190-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:01.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9609 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:56.765-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:39.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9608" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:03.463-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:56.553-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:01.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9608 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:55.287-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:38.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31744"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32124"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32082"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32187"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32043"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32006"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32183"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32139"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31801"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32194"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32134"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32161"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32155"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32024"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31724"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32126"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31884"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32021"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.2" test_ref="oval:org.mitre.oval:tst:32145"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:31660"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.2" test_ref="oval:org.mitre.oval:tst:32157"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9606" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2664.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2725"/>
        <description>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2664.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.744-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:55.744-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:00.236-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9606 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:06.662-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:37.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9605" version="5" class="vulnerability">
      <metadata>
        <title>packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4680"/>
        <description>packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:09.474-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:55.446-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:59.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9605 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:13.502-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:36.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9604" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:26.455-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.903-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:59.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9604 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:08.087-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:36.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9601" version="5" class="vulnerability">
      <metadata>
        <title>tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1279" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1279"/>
        <description>tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:01.848-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:54.175-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:58.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9601 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:20.339-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:34.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libpcap is earlier than 14:0.7.2-7.E3.5" test_ref="oval:org.mitre.oval:tst:31652"/>
            <criterion comment="tcpdump is earlier than 14:3.7.2-7.E3.5" test_ref="oval:org.mitre.oval:tst:31836"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" test_ref="oval:org.mitre.oval:tst:31864"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-9.RHEL4" test_ref="oval:org.mitre.oval:tst:30922"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" test_ref="oval:org.mitre.oval:tst:31788"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9600" version="5" class="vulnerability">
      <metadata>
        <title>The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834"/>
        <description>The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:09.524-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.633-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:58.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9600 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:18:04.409-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:34.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38663"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38680"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38674"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38654"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38700"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38368"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38726"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38390"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38547"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38412"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38701"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9599" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0585"/>
        <description>Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:43.432-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.363-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:57.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9599 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:12.920-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:33.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libsoup is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:38290"/>
            <criterion comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:38001"/>
            <criterion comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" test_ref="oval:org.mitre.oval:tst:38097"/>
            <criterion comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" test_ref="oval:org.mitre.oval:tst:38304"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38189"/>
            <criterion comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" test_ref="oval:org.mitre.oval:tst:38136"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9598" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1469"/>
        <description>Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:11.437-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:53.117-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:57.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9598 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:52.826-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:33.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9597" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660"/>
        <description>PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:20.548-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:52.368-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9597 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:02.456-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:32.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9594" version="5" class="vulnerability">
      <metadata>
        <title>The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2464"/>
        <description>The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.300-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:51.649-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:56.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9594 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:40.389-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:31.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9593" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2810" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2810"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:35.710-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:51.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:55.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9593 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:30.638-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:30.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9591" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0711"/>
        <description>MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:49.680-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:50.196-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9591 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:06.049-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:29.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31367"/>
            <criterion comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31299"/>
            <criterion comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" test_ref="oval:org.mitre.oval:tst:31391"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30977"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31612"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31452"/>
            <criterion comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31294"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9590" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0159"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:17.168-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:49.635-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9590 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:08.452-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:28.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39910"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40282"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40001"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40160"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39327"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39963"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39749"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40277"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39865"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40145"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40087"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40185"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40258"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40130"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40147"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40264"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9589" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:18.301-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:49.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:54.047-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9589 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:49.121-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:28.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31786"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31975"/>
            <criterion comment="httpd is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31650"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31790"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31890"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31948"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31906"/>
            <criterion comment="httpd is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:32146"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9587" version="5" class="vulnerability">
      <metadata>
        <title>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0075"/>
        <description>prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:34.569-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:48.876-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:53.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9587 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:37.565-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:27.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" test_ref="oval:org.mitre.oval:tst:30441"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" test_ref="oval:org.mitre.oval:tst:30956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9584" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:31.405-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:47.790-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:52.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9584 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:54.928-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:26.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9579" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1455"/>
        <description>Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.137-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:46.138-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:50.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9579 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:47.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:25.380-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" test_ref="oval:org.mitre.oval:tst:31698"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:32002"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31962"/>
            <criterion comment="freeradius is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31992"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" test_ref="oval:org.mitre.oval:tst:31999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9577" version="5" class="vulnerability">
      <metadata>
        <title>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
        <description>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:05.981-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:45.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:49.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9577 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:58.410-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:24.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37941"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37561"/>
            <criterion comment="httpd is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37595"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37897"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37670"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37862"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37679"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37575"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37895"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37730"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:36990"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9575" version="5" class="vulnerability">
      <metadata>
        <title>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3625"/>
        <description>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:39.436-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:44.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:49.193-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9575 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:52.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:23.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9573" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211"/>
        <description>Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:54.309-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:44.153-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:48.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9573 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:33.641-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:22.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9572" version="5" class="vulnerability">
      <metadata>
        <title>The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2120"/>
        <description>The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:30.281-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.884-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:48.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9572 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:43.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:22.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9571" version="5" class="vulnerability">
      <metadata>
        <title>VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138"/>
        <description>VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:07.405-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.574-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:47.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9571 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:25.659-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:21.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30321"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:31244"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30519"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:30858"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.1" test_ref="oval:org.mitre.oval:tst:31167"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31180"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31161"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31316"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31312"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31163"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9570" version="5" class="vulnerability">
      <metadata>
        <title>The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3443"/>
        <description>The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:01.689-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:43.069-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:47.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9570 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:04.805-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:20.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37606"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37736"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37427"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37760"/>
            <criterion comment="ruby is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37497"/>
            <criterion comment="irb is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37751"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:36770"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9569" version="5" class="vulnerability">
      <metadata>
        <title>Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2498"/>
        <description>Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:49.732-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:42.575-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:46.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9569 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:29.809-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:20.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31517"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32191"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32009"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31823"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31971"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:32008"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-25.ent" test_ref="oval:org.mitre.oval:tst:31197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32052"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31200"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31503"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32192"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31957"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31771"/>
            <criterion comment="php is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31974"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31734"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32178"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31386"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32029"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:31677"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32000"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.8" test_ref="oval:org.mitre.oval:tst:32062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9567" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235"/>
        <description>Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:47.444-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:41.914-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:46.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9567 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:18.946-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:19.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31090"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31317"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31165"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31297"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31259"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30906"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31029"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:31014"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" test_ref="oval:org.mitre.oval:tst:30920"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9566" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0457"/>
        <description>Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:19.941-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:41.637-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:45.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9566 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:34.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:18.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9564" version="5" class="vulnerability">
      <metadata>
        <title>The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4377"/>
        <description>The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:01.901-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:40.893-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:45.228-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9564 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:54.068-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:18.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9563" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1615"/>
        <description>Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:38.739-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:40.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:44.670-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9563 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:14.697-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:17.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36697"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36610"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36727"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35799"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35977"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36772"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36502"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36670"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36665"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:35765"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36539"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.21.el5" test_ref="oval:org.mitre.oval:tst:36637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9562" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0384"/>
        <description>Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:47.619-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.963-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:44.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9562 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:44.513-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:17.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9561" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3044"/>
        <description>Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.818-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.578-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9561 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:27.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:16.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9560" version="5" class="vulnerability">
      <metadata>
        <title>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0001"/>
        <description>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:16.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:39.301-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.545-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9560 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:13.741-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:15.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33775"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33751"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33264"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33777"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33668"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33639"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33564"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33538"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9559" version="5" class="vulnerability">
      <metadata>
        <title>MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2691"/>
        <description>MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:14.656-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:38.952-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:43.233-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9559 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:21.778-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:15.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37045"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37456"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:36967"/>
            <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
            <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
            <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9558" version="5" class="vulnerability">
      <metadata>
        <title>The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029"/>
        <description>The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.060-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:38.331-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:42.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9558 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:13.538-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:14.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37830"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37968"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37984"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37633"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37352"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38043"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37989"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37908"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37748"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37825"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38161"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37996"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38259"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37366"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37939"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38003"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38294"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38054"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:37318"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38086"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38226"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.el5" test_ref="oval:org.mitre.oval:tst:38094"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9557" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0411"/>
        <description>Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:43.242-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.939-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:42.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9557 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:24.577-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:14.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="hpijs is earlier than 0:1.3-32.1.13" test_ref="oval:org.mitre.oval:tst:36464"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.13" test_ref="oval:org.mitre.oval:tst:36326"/>
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.13" test_ref="oval:org.mitre.oval:tst:36149"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:36082"/>
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:35551"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:36061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36325"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35805"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36363"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9555" version="5" class="vulnerability">
      <metadata>
        <title>arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1514"/>
        <description>arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:08.201-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:37.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:41.604-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9555 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:31.900-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:13.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37470"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37734"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37826"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37656"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37782"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37747"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37811"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37951"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37485"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9553" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2549"/>
        <description>Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:47.863-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:36.838-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:40.846-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9553 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:03.212-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:12.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-16" test_ref="oval:org.mitre.oval:tst:31035"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-16" test_ref="oval:org.mitre.oval:tst:31372"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:2.0.2-16.3" test_ref="oval:org.mitre.oval:tst:31247"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-16.3" test_ref="oval:org.mitre.oval:tst:31492"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9551" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1234"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:45.945-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.820-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:39.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9551 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:17.482-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:11.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9550" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2629"/>
        <description>Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:34.078-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:39.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9550 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:34.968-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:11.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9548" version="5" class="vulnerability">
      <metadata>
        <title>Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0195"/>
        <description>Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.246-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:35.106-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:38.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9548 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:18.503-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:10.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el3" test_ref="oval:org.mitre.oval:tst:32265"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el4" test_ref="oval:org.mitre.oval:tst:32721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9547" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870"/>
        <description>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:43.525-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:34.479-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:38.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9547 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:37.382-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:09.540-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34371"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34445"/>
            <criterion comment="yelp is earlier than 0:2.16.0-15.el5" test_ref="oval:org.mitre.oval:tst:33445"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34323"/>
            <criterion comment="devhelp is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34204"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34162"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9545" version="5" class="vulnerability">
      <metadata>
        <title>lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269"/>
        <description>lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:18.233-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.926-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:37.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9545 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:25.465-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:09.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:30882"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31108"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:30919"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31056"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9544" version="5" class="vulnerability">
      <metadata>
        <title>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1269"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:35.089-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.706-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:37.471-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9544 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:53.391-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:08.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el3" test_ref="oval:org.mitre.oval:tst:31762"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el4" test_ref="oval:org.mitre.oval:tst:31939"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9543" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142"/>
        <description>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:26.755-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:33.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:36.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9543 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:56.986-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:08.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9541" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689"/>
        <description>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:25.089-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:32.057-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:35.730-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9541 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:03.422-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:07.632-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:39402"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:39743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:39677"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:38993"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-25.el5_4.1" test_ref="oval:org.mitre.oval:tst:39605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9539" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5000"/>
        <description>Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:15.632-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:31.458-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:35.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9539 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:50.570-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:06.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:35773"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:36016"/>
            <criterion comment="httpd is earlier than 0:2.0.46-70.ent" test_ref="oval:org.mitre.oval:tst:35281"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35606"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35973"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35916"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35852"/>
            <criterion comment="httpd is earlier than 0:2.0.52-38.ent.2" test_ref="oval:org.mitre.oval:tst:35768"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35953"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35668"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35991"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_1.3" test_ref="oval:org.mitre.oval:tst:35696"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9538" version="5" class="vulnerability">
      <metadata>
        <title>slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2499" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2499"/>
        <description>slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.098-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:31.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9538 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:00.149-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:06.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="slocate is earlier than 0:2.7-3.RHEL3.6" test_ref="oval:org.mitre.oval:tst:31533"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="slocate is earlier than 0:2.7-13.el4.6" test_ref="oval:org.mitre.oval:tst:31470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9537" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5469"/>
        <description>Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:11.323-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.958-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.630-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9537 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:58.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:05.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9536" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3608" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608"/>
        <description>Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:42.153-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.515-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:34.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9536 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:38.769-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:05.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39430"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39290"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38854"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39346"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39383"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38836"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9535" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:57.773-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:30.260-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9535 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:45.867-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:04.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9534" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1464"/>
        <description>Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:29.313-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.978-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9534 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:55.829-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:04.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9533" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0593" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:32.456-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.655-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9533 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:38.233-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9532" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1852" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1852"/>
        <description>Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:24.195-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.448-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:33.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9532 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:15.881-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32125"/>
          <criterion comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32141"/>
          <criterion comment="kdenetwork is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:31965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9531" version="5" class="vulnerability">
      <metadata>
        <title>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2274"/>
        <description>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:59.601-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:29.170-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:32.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9531 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:57.455-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:03.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9529" version="5" class="vulnerability">
      <metadata>
        <title>The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4059"/>
        <description>The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:59.233-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:28.415-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:31.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9529 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:51.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:02.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9528" version="5" class="vulnerability">
      <metadata>
        <title>Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3.  NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie.  Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability.  NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253"/>
        <description>Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3.  NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie.  Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability.  NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:19.553-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:27.878-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:31.461-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9528 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:01.521-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:01.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9526" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210"/>
        <description>Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:27.268-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:30.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9526 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:58.883-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:20:00.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38258"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38635"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38709"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38670"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9525" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633"/>
        <description>Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:13.439-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:30.174-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9525 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:41:07.731-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:59.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38877"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38938"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39012"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39048"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38799"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39160"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39030"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38637"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38231"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:39133"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.7.EL" test_ref="oval:org.mitre.oval:tst:38985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9522" version="5" class="vulnerability">
      <metadata>
        <title>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1760"/>
        <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:19.772-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:26.010-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9522 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:56.532-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:58.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.7.2-6" test_ref="oval:org.mitre.oval:tst:31795"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.15-2" test_ref="oval:org.mitre.oval:tst:31426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9521" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010"/>
        <description>Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:25.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:25.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:29.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9521 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:32.845-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:57.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9520" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1218"/>
        <description>Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:12.310-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:25.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9520 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:26.881-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:57.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-12.el4" test_ref="oval:org.mitre.oval:tst:34426"/>
            <criterion comment="libpcap is earlier than 14:0.8.3-12.el4" test_ref="oval:org.mitre.oval:tst:34317"/>
            <criterion comment="tcpdump is earlier than 14:3.8.2-12.el4" test_ref="oval:org.mitre.oval:tst:33439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="arpwatch is earlier than 14:2.1a13-18.el5" test_ref="oval:org.mitre.oval:tst:34286"/>
            <criterion comment="libpcap-devel is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34191"/>
            <criterion comment="libpcap is earlier than 14:0.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:34045"/>
            <criterion comment="tcpdump is earlier than 14:3.9.4-11.el5" test_ref="oval:org.mitre.oval:tst:33937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9519" version="5" class="vulnerability">
      <metadata>
        <title>The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1949"/>
        <description>The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:57.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.801-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9519 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:43.243-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36194"/>
            <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36294"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:35940"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9516" version="5" class="vulnerability">
      <metadata>
        <title>mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3081"/>
        <description>mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:20.992-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.580-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9516 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:59.958-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9515" version="5" class="vulnerability">
      <metadata>
        <title>The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3083"/>
        <description>The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:09.828-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:24.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:28.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9515 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:47.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:56.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="krb5-workstation is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32665"/>
          <criterion comment="krb5 is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32887"/>
          <criterion comment="krb5-libs is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32980"/>
          <criterion comment="krb5-server is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32772"/>
          <criterion comment="krb5-devel is earlier than 0:1.3.4-33" test_ref="oval:org.mitre.oval:tst:32806"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9514" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0910"/>
        <description>Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:55.962-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:23.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:27.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9514 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:50.992-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:55.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9513" version="5" class="vulnerability">
      <metadata>
        <title>The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1883"/>
        <description>The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:50.899-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:23.283-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:26.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9513 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:39:59.557-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:54.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9511" version="5" class="vulnerability">
      <metadata>
        <title>fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4210"/>
        <description>fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:28.578-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:22.355-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9511 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:05.196-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:53.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37470"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37734"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37826"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37656"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37782"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37432"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37747"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37811"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37951"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37485"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37778"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37855"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37870"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37881"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37504"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37738"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37774"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37247"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37715"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37954"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37668"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" test_ref="oval:org.mitre.oval:tst:37947"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9510" version="5" class="vulnerability">
      <metadata>
        <title>SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1858"/>
        <description>SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:18.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.998-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9510 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:36:00.135-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:40:40.120-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:53.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9509" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1766"/>
        <description>Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:14.265-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.815-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9509 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:30.134-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:52.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.5-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31840"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9508" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0747"/>
        <description>Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:34.261-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.548-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:25.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9508 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:13.977-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:52.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32599"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32616"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32106"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32605"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32417"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9507" version="5" class="vulnerability">
      <metadata>
        <title>The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725"/>
        <description>The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:32.649-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:21.152-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9507 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:15.502-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="hpijs is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38025"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38598"/>
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38506"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38482"/>
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38656"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38408"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38588"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38629"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38457"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9506" version="5" class="vulnerability">
      <metadata>
        <title>libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"/>
        <description>libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:24.099-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.810-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9506 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:06.388-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:39170"/>
            <criterion comment="libvorbis is earlier than 1:1.0-11.el3" test_ref="oval:org.mitre.oval:tst:38631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38645"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:39192"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_3.3" test_ref="oval:org.mitre.oval:tst:39166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9504" version="5" class="vulnerability">
      <metadata>
        <title>mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1636"/>
        <description>mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:59.395-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.585-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:24.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9504 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:50.644-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:51.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32079"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31928"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31694"/>
          <criterion comment="mysql-server is earlier than 0:4.1.12-3.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9503" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3186"/>
        <description>Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:47.594-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:20.287-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:23.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9503 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:54.942-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:50.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32203"/>
            <criterion comment="gtk2 is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32214"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32393"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32388"/>
            <criterion comment="gtk2-devel is earlier than 0:2.2.4-19" test_ref="oval:org.mitre.oval:tst:32156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32239"/>
            <criterion comment="gtk2 is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32313"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32331"/>
            <criterion comment="gtk2-devel is earlier than 0:2.4.13-18" test_ref="oval:org.mitre.oval:tst:32250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9502" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0174"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:10.285-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:19.747-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9502 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:17.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:49.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9501" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392"/>
        <description>The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:04.877-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:19.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9501 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:49.536-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:49.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9500" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1420"/>
        <description>Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:24.692-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:18.881-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:22.091-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9500 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:20.632-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:48.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36659"/>
            <criterion comment="libvorbis is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36519"/>
            <criterion comment="libvorbis is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36439"/>
            <criterion comment="libvorbis is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9497" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2472"/>
        <description>Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:18.902-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:18.435-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:21.593-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9497 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:56.590-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:48.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9496" version="5" class="vulnerability">
      <metadata>
        <title>KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0062"/>
        <description>KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:21.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:17.980-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:21.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9496 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:20.416-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:47.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36272"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36493"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36531"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36304"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36522"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36541"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36418"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36371"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36482"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36318"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36285"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36069"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36233"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9494" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309"/>
        <description>Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:18.740-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:17.298-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:20.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9494 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:22.323-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:46.453-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9493" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844"/>
        <description>Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:31.463-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:16.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:19.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9493 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:38.382-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:45.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9492" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0597"/>
        <description>Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:18.085-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:16.459-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:19.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9492 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:41.664-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:45.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36392"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36393"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.51" test_ref="oval:org.mitre.oval:tst:36450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:35932"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:36243"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" test_ref="oval:org.mitre.oval:tst:36438"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9491" version="5" class="vulnerability">
      <metadata>
        <title>EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2787" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2787"/>
        <description>EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:21.461-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:15.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:18.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9491 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:35.760-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:44.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9488" version="5" class="vulnerability">
      <metadata>
        <title>The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6120"/>
        <description>The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:36.652-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:14.892-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:17.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9488 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:17.716-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:43.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9487" version="5" class="vulnerability">
      <metadata>
        <title>The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1041"/>
        <description>The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:51.290-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:14.633-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:17.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9487 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:49.588-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:42.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9484" version="5" class="vulnerability">
      <metadata>
        <title>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1698"/>
        <description>WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:24.152-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.426-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:16.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9484 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:30.909-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.1.3-6.13" test_ref="oval:org.mitre.oval:tst:38767"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.1.3-6.13" test_ref="oval:org.mitre.oval:tst:38487"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:37977"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:38299"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38102"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38389"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38720"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9483" version="5" class="vulnerability">
      <metadata>
        <title>BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1058"/>
        <description>BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:14.161-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:13.232-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:16.253-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9483 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:55.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="busybox-anaconda is earlier than 0:1.00.rc1-7.el4" test_ref="oval:org.mitre.oval:tst:33230"/>
          <criterion comment="busybox is earlier than 0:1.00.rc1-7.el4" test_ref="oval:org.mitre.oval:tst:33750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9482" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5740"/>
        <description>Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:09.293-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.944-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9482 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:57.587-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:41.187-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33205"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL3.1" test_ref="oval:org.mitre.oval:tst:33170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:32550"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.4-EL4.1" test_ref="oval:org.mitre.oval:tst:33152"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9481" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2440"/>
        <description>Heap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:19.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.626-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9481 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:22.562-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:40.696-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33189"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33318"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33102"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33080"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-24" test_ref="oval:org.mitre.oval:tst:33315"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33269"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33326"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32926"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:32622"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" test_ref="oval:org.mitre.oval:tst:33361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9480" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5378"/>
        <description>Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:23.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.285-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:15.244-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9480 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:15.516-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:40.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tix is earlier than 0:8.1.4-92.8" test_ref="oval:org.mitre.oval:tst:36200"/>
            <criterion comment="tclx is earlier than 0:8.3-92.8" test_ref="oval:org.mitre.oval:tst:35800"/>
            <criterion comment="tcl-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:35961"/>
            <criterion comment="expect-devel is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:36175"/>
            <criterion comment="tcltk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36169"/>
            <criterion comment="itcl is earlier than 0:3.2-92.8" test_ref="oval:org.mitre.oval:tst:35879"/>
            <criterion comment="tcl is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36313"/>
            <criterion comment="expect is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:35369"/>
            <criterion comment="tk-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36316"/>
            <criterion comment="tk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36018"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tk-devel is earlier than 0:8.4.7-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36356"/>
            <criterion comment="tk is earlier than 0:8.4.7-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36225"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9475" version="5" class="vulnerability">
      <metadata>
        <title>The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0052"/>
        <description>The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:02.110-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:12.068-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:14.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9475 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:12.831-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:39.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-25.rhel3.5" test_ref="oval:org.mitre.oval:tst:32725"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.3" test_ref="oval:org.mitre.oval:tst:32480"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9473" version="5" class="vulnerability">
      <metadata>
        <title>The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141"/>
        <description>The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:12.964-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:11.563-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:14.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9473 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:38.712-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:39.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9472" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3055"/>
        <description>Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:14.540-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:11.156-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9472 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:54.579-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:38.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9470" version="5" class="vulnerability">
      <metadata>
        <title>slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0658"/>
        <description>slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:15.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:10.434-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:13.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9470 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:57.943-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:37.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36122"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36157"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:35412"/>
            <criterion comment="openldap is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36270"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:36239"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.4" test_ref="oval:org.mitre.oval:tst:35877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35700"/>
            <criterion comment="openldap-devel is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35900"/>
            <criterion comment="openldap-clients is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36273"/>
            <criterion comment="openldap is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36158"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:36065"/>
            <criterion comment="openldap-servers is earlier than 0:2.3.27-8.el5_1.3" test_ref="oval:org.mitre.oval:tst:35300"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9468" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3632"/>
        <description>Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:10.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:09.965-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:12.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9468 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:10.632-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:36.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9467" version="5" class="vulnerability">
      <metadata>
        <title>The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3181"/>
        <description>The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:46.155-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:09.713-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:12.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9467 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:18.812-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:36.536-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9463" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:19.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.911-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:11.727-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9463 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:27.084-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:35.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9461" version="5" class="vulnerability">
      <metadata>
        <title>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473"/>
        <description>neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:43.398-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.488-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:11.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9461 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:31.582-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:34.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38525"/>
            <criterion comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38882"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39020"/>
            <criterion comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39410"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9460" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0839"/>
        <description>Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:47.573-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:08.228-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:10.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9460 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:28.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:34.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9459" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357"/>
        <description>Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:42.242-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:07.602-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:10.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9459 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:20.171-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:33.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38173"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38181"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38221"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38323"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38337"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:37355"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38135"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38326"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38186"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38184"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38228"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37943"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37433"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38309"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38278"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9456" version="5" class="vulnerability">
      <metadata>
        <title>A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3813"/>
        <description>A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:54.663-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:07.201-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:09.830-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9456 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:03.332-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:32.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="perl-suidperl is earlier than 3:5.8.5-36.RHEL4" test_ref="oval:org.mitre.oval:tst:32691"/>
          <criterion comment="perl is earlier than 3:5.8.5-36.RHEL4" test_ref="oval:org.mitre.oval:tst:32640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9455" version="5" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303"/>
        <description>The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:50.725-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:06.661-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:09.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9455 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:42.824-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:32.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9454" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3740"/>
        <description>Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:28.193-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:05.836-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:08.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9454 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:14.116-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:31.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32914"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32731"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32743"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33049"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33018"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32923"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33030"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32967"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32863"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32067"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32995"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32642"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32901"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32927"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32766"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32821"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32286"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32798"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32943"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32071"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32966"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32931"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32847"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32849"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32945"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32827"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32897"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:33027"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32324"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-113.EL" test_ref="oval:org.mitre.oval:tst:32850"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32455"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32518"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32775"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32899"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32949"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32941"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33005"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32769"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32227"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33008"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32830"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32907"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:33034"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32741"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32935"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32792"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32908"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.2" test_ref="oval:org.mitre.oval:tst:32709"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9453" version="5" class="vulnerability">
      <metadata>
        <title>The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895"/>
        <description>The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:22.749-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:05.111-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:07.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9453 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:17.289-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:30.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38128"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38668"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38883"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38948"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38732"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38969"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38991"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39056"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38817"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39009"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38672"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9449" version="5" class="vulnerability">
      <metadata>
        <title>The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5052"/>
        <description>The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:01.420-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:04.254-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:06.875-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9449 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:11.230-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:28.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9448" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840"/>
        <description>Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.305-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.957-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:06.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9448 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:29.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:28.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9446" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0179"/>
        <description>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:46.891-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.404-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9446 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:59.471-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:27.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9445" version="5" class="vulnerability">
      <metadata>
        <title>pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2069"/>
        <description>pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:33.275-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:03.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9445 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:29.982-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:27.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openldap-devel is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:32018"/>
            <criterion comment="openldap-clients is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:31815"/>
            <criterion comment="nss_ldap is earlier than 0:207-17" test_ref="oval:org.mitre.oval:tst:32179"/>
            <criterion comment="openldap is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:32086"/>
            <criterion comment="openldap-servers is earlier than 0:2.0.27-20" test_ref="oval:org.mitre.oval:tst:31961"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="compat-openldap is earlier than 0:2.1.30-4" test_ref="oval:org.mitre.oval:tst:32065"/>
            <criterion comment="openldap-devel is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32089"/>
            <criterion comment="openldap-clients is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:31874"/>
            <criterion comment="nss_ldap is earlier than 0:226-10" test_ref="oval:org.mitre.oval:tst:31977"/>
            <criterion comment="openldap is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:31301"/>
            <criterion comment="openldap-servers-sql is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32188"/>
            <criterion comment="openldap-servers is earlier than 0:2.2.13-4" test_ref="oval:org.mitre.oval:tst:32059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9444" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074"/>
        <description>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:10.861-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:02.701-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:05.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9444 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:26.994-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:26.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9442" version="5" class="vulnerability">
      <metadata>
        <title>snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4837"/>
        <description>snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:42.892-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:02.154-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:04.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9442 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:58.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:25.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9439" version="5" class="vulnerability">
      <metadata>
        <title>drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537"/>
        <description>drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:58.267-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:01.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:04.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9439 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:20.428-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:25.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39702"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39797"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39763"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39709"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39503"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39617"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39773"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39516"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39093"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39662"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.19.EL" test_ref="oval:org.mitre.oval:tst:39657"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39645"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39650"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39813"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39095"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39770"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39099"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39700"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39408"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39590"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39719"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:39789"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.10.1.el5" test_ref="oval:org.mitre.oval:tst:38905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9437" version="5" class="vulnerability">
      <metadata>
        <title>The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3624"/>
        <description>The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:25.836-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:01.149-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:03.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9437 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:24.591-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:24.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9434" version="5" class="vulnerability">
      <metadata>
        <title>The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1920" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1920"/>
        <description>The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:34.816-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:12:00.324-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:02.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9434 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:03.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:23.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdelibs is earlier than 6:3.3.1-3.11" test_ref="oval:org.mitre.oval:tst:31875"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.11" test_ref="oval:org.mitre.oval:tst:31922"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9432" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2807"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:35.473-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:59.492-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:01.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9432 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:09.431-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:22.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9424" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2872"/>
        <description>Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:35.882-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:57.755-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:13:00.128-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9424 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:45.125-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:19.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9421" version="5" class="vulnerability">
      <metadata>
        <title>slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0277" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0277"/>
        <description>slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.380-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:57.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:59.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9421 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:43.684-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:18.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9417" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0421"/>
        <description>Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:09.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:56.197-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:58.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9417 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:21.761-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:17.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.2.5-10" test_ref="oval:org.mitre.oval:tst:40152"/>
            <criterion comment="pango is earlier than 0:1.2.5-10" test_ref="oval:org.mitre.oval:tst:39329"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.6.0-16.el4_8" test_ref="oval:org.mitre.oval:tst:39573"/>
            <criterion comment="evolution28-pango-devel is earlier than 0:1.14.9-13.el4_8" test_ref="oval:org.mitre.oval:tst:40323"/>
            <criterion comment="pango is earlier than 0:1.6.0-16.el4_8" test_ref="oval:org.mitre.oval:tst:39891"/>
            <criterion comment="evolution28-pango is earlier than 0:1.14.9-13.el4_8" test_ref="oval:org.mitre.oval:tst:39360"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:40132"/>
            <criterion comment="pango is earlier than 0:1.14.9-8.el5" test_ref="oval:org.mitre.oval:tst:40189"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9414" version="5" class="vulnerability">
      <metadata>
        <title>The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615"/>
        <description>The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:49.763-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:55.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:57.734-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9414 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:08.899-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:16.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-6.el3" test_ref="oval:org.mitre.oval:tst:39353"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39708"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39368"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39729"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39606"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39458"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39406"/>
            <criterion comment="finch is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39382"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39309"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el4" test_ref="oval:org.mitre.oval:tst:39454"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39342"/>
            <criterion comment="libpurple is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39335"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39751"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39174"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39298"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39584"/>
            <criterion comment="finch is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39392"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39508"/>
            <criterion comment="pidgin is earlier than 0:2.6.3-2.el5" test_ref="oval:org.mitre.oval:tst:39728"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9413" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4514"/>
        <description>Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:29.075-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:55.275-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:57.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9413 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:56.540-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:15.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libgsf is earlier than 0:1.6.0-7" test_ref="oval:org.mitre.oval:tst:33304"/>
            <criterion comment="libgsf-devel is earlier than 0:1.6.0-7" test_ref="oval:org.mitre.oval:tst:32479"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libgsf is earlier than 0:1.10.1-2" test_ref="oval:org.mitre.oval:tst:33333"/>
            <criterion comment="libgsf-devel is earlier than 0:1.10.1-2" test_ref="oval:org.mitre.oval:tst:33257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9412" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0007"/>
        <description>Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:59.884-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:54.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9412 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:23.076-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:14.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36107"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36600"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36529"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36526"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36442"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36238"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36463"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36480"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35876"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36532"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36278"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35724"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36560"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9411" version="5" class="vulnerability">
      <metadata>
        <title>sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2104"/>
        <description>sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:49.875-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:54.230-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9411 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:55.250-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:14.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.7.2-9" test_ref="oval:org.mitre.oval:tst:31930"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sysreport is earlier than 0:1.3.15-5" test_ref="oval:org.mitre.oval:tst:31910"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9409" version="5" class="vulnerability">
      <metadata>
        <title>The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228"/>
        <description>The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:28.297-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:53.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:56.070-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9409 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:19.184-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:13.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39477"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38676"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39556"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39526"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38895"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39250"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39485"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39492"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39608"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39456"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39277"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9408" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100"/>
        <description>Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:47.264-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:53.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:55.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9408 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:02:57.349-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:13.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31334"/>
            <criterion comment="xemacs is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31358"/>
            <criterion comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" test_ref="oval:org.mitre.oval:tst:31061"/>
            <criterion comment="emacs-el is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:31186"/>
            <criterion comment="emacs-leim is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:30740"/>
            <criterion comment="emacs is earlier than 0:21.3-4.1" test_ref="oval:org.mitre.oval:tst:31379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:30840"/>
            <criterion comment="emacs-nox is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31124"/>
            <criterion comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31326"/>
            <criterion comment="emacs-el is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:30860"/>
            <criterion comment="emacs-leim is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31288"/>
            <criterion comment="emacs is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31389"/>
            <criterion comment="emacs-common is earlier than 0:21.3-19.EL.1" test_ref="oval:org.mitre.oval:tst:31328"/>
            <criterion comment="xemacs is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31171"/>
            <criterion comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:30965"/>
            <criterion comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" test_ref="oval:org.mitre.oval:tst:31034"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9407" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1721"/>
        <description>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:13.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:52.964-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:55.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9407 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:02.286-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:12.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9405" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:42.534-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:52.201-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:54.433-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9405 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:09.273-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:11.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9402" version="5" class="vulnerability">
      <metadata>
        <title>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0069"/>
        <description>The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.609-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:51.611-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:53.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9402 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:10.954-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:10.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:31098"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30910"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:31254"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30835"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.3" test_ref="oval:org.mitre.oval:tst:30437"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31180"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31161"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31316"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31312"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.40E.4" test_ref="oval:org.mitre.oval:tst:31163"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9397" version="5" class="vulnerability">
      <metadata>
        <title>The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721"/>
        <description>The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:00.671-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:50.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9397 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:10.317-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:09.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:37861"/>
            <criterion comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:38005"/>
            <criterion comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" test_ref="oval:org.mitre.oval:tst:38171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37534"/>
            <criterion comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37722"/>
            <criterion comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:37227"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9396" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3858"/>
        <description>Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:57.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:50.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.483-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9396 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:13.301-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:08.817-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9393" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3964"/>
        <description>Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:32.388-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.961-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:52.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9393 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:25.066-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:08.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.7" test_ref="oval:org.mitre.oval:tst:32680"/>
            <criterion comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.3" test_ref="oval:org.mitre.oval:tst:32681"/>
            <criterion comment="openmotif is earlier than 0:2.2.3-5.RHEL3.3" test_ref="oval:org.mitre.oval:tst:32716"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32013"/>
            <criterion comment="openmotif-devel is earlier than 0:2.2.3-10.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32468"/>
            <criterion comment="openmotif is earlier than 0:2.2.3-10.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32612"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9392" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308"/>
        <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:41.137-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9392 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:43.369-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:31219"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-22.el3" test_ref="oval:org.mitre.oval:tst:30876"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:31174"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-8" test_ref="oval:org.mitre.oval:tst:30884"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9390" version="5" class="vulnerability">
      <metadata>
        <title>The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1862"/>
        <description>The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:37.254-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.442-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9390 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:11.351-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9388" version="5" class="vulnerability">
      <metadata>
        <title>kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2494"/>
        <description>kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:14.333-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:49.243-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:51.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9388 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:00.302-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:07.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdebase is earlier than 6:3.3.1-5.13" test_ref="oval:org.mitre.oval:tst:32841"/>
          <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.13" test_ref="oval:org.mitre.oval:tst:32807"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9386" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2800"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.390-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:48.607-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:50.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9386 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:27.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:06.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9384" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3988"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:09.517-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.977-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:49.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9384 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:23.149-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:04.935-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9379" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999"/>
        <description>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.163-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:47.184-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:48.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9379 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:29.519-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:03.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nfs-utils-lib-devel is earlier than 0:1.0.6-8.z1" test_ref="oval:org.mitre.oval:tst:34626"/>
            <criterion comment="nfs-utils-lib is earlier than 0:1.0.6-8.z1" test_ref="oval:org.mitre.oval:tst:35367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nfs-utils-lib-devel is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35168"/>
            <criterion comment="nfs-utils-lib is earlier than 0:1.0.8-7.2.z2" test_ref="oval:org.mitre.oval:tst:35408"/>
            <criterion comment="krb5-workstation is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34835"/>
            <criterion comment="krb5 is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35134"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34559"/>
            <criterion comment="krb5-server is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:35091"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-29" test_ref="oval:org.mitre.oval:tst:34927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9376" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5507"/>
        <description>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:41.611-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:46.143-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.971-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9376 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:44.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:02.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9375" version="5" class="vulnerability">
      <metadata>
        <title>The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182"/>
        <description>The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:13.424-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.707-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9375 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:15.596-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:01.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.6.4-8.el4" test_ref="oval:org.mitre.oval:tst:40755"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40435"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40552"/>
            <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40721"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40480"/>
            <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40813"/>
            <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40221"/>
            <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40385"/>
            <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:40828"/>
            <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40814"/>
            <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:40524"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40620"/>
            <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40722"/>
            <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:40273"/>
            <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9373" version="5" class="vulnerability">
      <metadata>
        <title>The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1168"/>
        <description>The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:42.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.490-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:47.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9373 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:36.486-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:01.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ncompress is earlier than 0:4.2.4-39.rhel3" test_ref="oval:org.mitre.oval:tst:32891"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ncompress is earlier than 0:4.2.4-43.rhel4" test_ref="oval:org.mitre.oval:tst:32529"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9371" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5753"/>
        <description>Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:01.617-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:45.214-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9371 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:31.838-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9370" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738"/>
        <description>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:56.422-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.766-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9370 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:53.800-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32990"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32592"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.21" test_ref="oval:org.mitre.oval:tst:32812"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.46" test_ref="oval:org.mitre.oval:tst:32771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:32875"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:33058"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.14" test_ref="oval:org.mitre.oval:tst:33093"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46" test_ref="oval:org.mitre.oval:tst:32789"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9369" version="5" class="vulnerability">
      <metadata>
        <title>SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1190"/>
        <description>SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:52.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.505-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:46.089-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9369 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:44.183-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:19:00.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9367" version="5" class="vulnerability">
      <metadata>
        <title>The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4770"/>
        <description>The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:58.120-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:44.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:45.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9367 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:40.958-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:59.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:38057"/>
            <criterion comment="vnc is earlier than 0:4.0-0.beta4.1.8" test_ref="oval:org.mitre.oval:tst:38376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:38179"/>
            <criterion comment="vnc is earlier than 0:4.0-12.el4_7.1" test_ref="oval:org.mitre.oval:tst:38424"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38345"/>
            <criterion comment="vnc is earlier than 0:4.1.2-14.el5_3.1" test_ref="oval:org.mitre.oval:tst:38082"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9363" version="5" class="vulnerability">
      <metadata>
        <title>The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"/>
        <description>The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:30.129-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:43.544-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:44.985-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9363 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:51.358-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:58.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39637"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39671"/>
            <criterion comment="httpd is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39611"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39448"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39501"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:38802"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39716"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39551"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39267"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39640"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39613"/>
            <criterion comment="httpd is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39756"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9358" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136"/>
        <description>PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:37.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:42.412-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:43.815-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9358 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:55.956-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:56.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40180"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40440"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40426"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40220"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39618"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40140"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40502"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:39925"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40137"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40551"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.21-3" test_ref="oval:org.mitre.oval:tst:40106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40486"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40521"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40292"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40516"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40066"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40399"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40512"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40314"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40428"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40366"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40401"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40402"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40538"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:39839"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40515"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40505"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40251"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40253"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40509"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9349" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4168"/>
        <description>Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:32.480-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:41.334-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:42.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9349 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:43.399-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:54.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2" test_ref="oval:org.mitre.oval:tst:34690"/>
            <criterion comment="libexif is earlier than 0:0.5.12-5.1.0.2" test_ref="oval:org.mitre.oval:tst:34611"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5" test_ref="oval:org.mitre.oval:tst:34381"/>
            <criterion comment="libexif is earlier than 0:0.6.13-4.0.2.el5" test_ref="oval:org.mitre.oval:tst:34026"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9345" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247"/>
        <description>Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:08.972-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:40.585-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:41.928-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9345 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:50.234-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:53.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30936"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30803"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31436"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31064"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:30591"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31342"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31217"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31199"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31415"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31005"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" test_ref="oval:org.mitre.oval:tst:31233"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31336"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31398"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31229"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30946"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31215"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:30784"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31126"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31318"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31273"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31424"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31325"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9343" version="5" class="vulnerability">
      <metadata>
        <title>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1410"/>
        <description>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:51.394-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:40.121-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:41.453-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9343 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:45.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:53.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31824"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31255"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31711"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31608"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31726"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31681"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31497"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31715"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31510"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31754"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.10-1" test_ref="oval:org.mitre.oval:tst:31507"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31832"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31880"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31527"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31669"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31129"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31756"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31799"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31798"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31618"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31468"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.8-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31708"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9336" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476"/>
        <description>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:10.748-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:39.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:40.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9336 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:41.541-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:52.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="tar is earlier than 0:1.14-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:40247"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tar is earlier than 2:1.15.1-23.0.1.el5_4.2" test_ref="oval:org.mitre.oval:tst:39957"/>
            <criterion comment="cpio is earlier than 0:2.6-23.el5_4.1" test_ref="oval:org.mitre.oval:tst:40260"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9332" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2022"/>
        <description>Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:26.745-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:38.571-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:40.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9332 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:30.615-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:51.455-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.1.3-5.16" test_ref="oval:org.mitre.oval:tst:34248"/>
            <criterion comment="kdebase-devel is earlier than 6:3.1.3-5.16" test_ref="oval:org.mitre.oval:tst:34656"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.3.1-5.19.rhel4" test_ref="oval:org.mitre.oval:tst:34288"/>
            <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.19.rhel4" test_ref="oval:org.mitre.oval:tst:34025"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdebase is earlier than 6:3.5.4-13.6.el5" test_ref="oval:org.mitre.oval:tst:34519"/>
            <criterion comment="kdebase-devel is earlier than 6:3.5.4-13.6.el5" test_ref="oval:org.mitre.oval:tst:34351"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9329" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2360"/>
        <description>Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:56.990-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:36.210-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:37.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9329 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:41.079-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:49.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9327" version="5" class="vulnerability">
      <metadata>
        <title>Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547"/>
        <description>Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:30.003-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:35.536-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:37.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9327 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:01.298-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:49.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39593"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39549"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39548"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39554"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39686"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39415"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39557"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39560"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39587"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:39607"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.16.EL" test_ref="oval:org.mitre.oval:tst:38910"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39665"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39142"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39538"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39699"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39518"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39350"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39738"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39663"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39536"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39189"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39141"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" test_ref="oval:org.mitre.oval:tst:39179"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9325" version="5" class="vulnerability">
      <metadata>
        <title>The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1522"/>
        <description>The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:08.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:35.249-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:36.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9325 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:39.181-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:48.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9323" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2701"/>
        <description>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:36.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:34.736-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:36.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9323 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:52.604-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:48.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9321" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1806"/>
        <description>Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:09.584-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:34.314-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.937-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9321 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:23.944-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:47.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36608"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-10.el3" test_ref="oval:org.mitre.oval:tst:36928"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36978"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37295"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:36877"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" test_ref="oval:org.mitre.oval:tst:37292"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37321"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37312"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37160"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9318" version="5" class="vulnerability">
      <metadata>
        <title>The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1562"/>
        <description>The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.860-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.959-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9318 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:19.364-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:47.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9317" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2383"/>
        <description>CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:23.221-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.701-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9317 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:30.527-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:46.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:179-11.EL3" test_ref="oval:org.mitre.oval:tst:38121"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:192-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:37919"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="xterm is earlier than 0:215-5.el5_2.2" test_ref="oval:org.mitre.oval:tst:38031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9315" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors.  NOTE: Vector 2 might also lead to a hang.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1561"/>
        <description>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors.  NOTE: Vector 2 might also lead to a hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:05.445-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.407-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:35.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9315 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:40.386-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:46.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9314" version="5" class="vulnerability">
      <metadata>
        <title>libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3350"/>
        <description>libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:49.373-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:33.079-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9314 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:09:04.344-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:45.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:32066"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:31940"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31956"/>
            <criterion comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:32398"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31871"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38143"/>
            <criterion comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38622"/>
            <criterion comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38639"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9313" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3249"/>
        <description>Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:39.635-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9313 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:54.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:45.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9311" version="5" class="vulnerability">
      <metadata>
        <title>The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5619"/>
        <description>The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:04.377-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.505-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:34.139-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9311 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:22.132-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:44.646-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9310" version="5" class="vulnerability">
      <metadata>
        <title>The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0524"/>
        <description>The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:55.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:32.053-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:33.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9310 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:23.526-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:43.940-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31759"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:30948"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31858"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31704"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31679"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31505"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31329"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31673"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31737"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31787"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31830"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31383"/>
            <criterion comment="php is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31557"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31541"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31697"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31847"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31523"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31779"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31261"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9307" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0815"/>
        <description>Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:36.138-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:31.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:33.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9307 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:12.811-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:43.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9306" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076"/>
        <description>Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:57.303-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:31.009-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:32.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9306 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:22.710-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:42.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39378"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39359"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39036"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39270"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39397"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39118"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38466"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39081"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:38976"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39181"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39364"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39293"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9304" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5464"/>
        <description>Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:38.770-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:30.506-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:32.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9304 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:07.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:41.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32940"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33113"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32275"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33128"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32259"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32596"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33188"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32780"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33131"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33198"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33241"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33268"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33216"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32752"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32536"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32857"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33185"/>
            <criterion comment="firefox is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33140"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33088"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33118"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33171"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32856"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9303" version="5" class="vulnerability">
      <metadata>
        <title>The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4045"/>
        <description>The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:15.342-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:30.237-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9303 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:23.669-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:41.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35491"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35533"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9295" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:06.558-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.768-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:31.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9295 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:56.654-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:40.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="tar is earlier than 0:1.14-9.RHEL4" test_ref="oval:org.mitre.oval:tst:32074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9283" version="5" class="vulnerability">
      <metadata>
        <title>The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2102"/>
        <description>The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:40.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:29.369-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:30.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9283 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:07.306-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:40.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el3.3" test_ref="oval:org.mitre.oval:tst:32063"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el4.3" test_ref="oval:org.mitre.oval:tst:31738"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9280" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3089"/>
        <description>Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:52.146-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:28.836-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:30.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9280 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:04.417-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:39.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9279" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1392"/>
        <description>PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:35.170-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:28.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:29.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9279 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:43.842-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:38.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31759"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:30948"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31858"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31704"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31679"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31505"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31329"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31673"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31737"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31787"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31830"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31383"/>
            <criterion comment="php is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31557"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31541"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31697"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31847"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31523"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31779"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31261"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9270" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829"/>
        <description>Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:32.952-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:27.814-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:29.169-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9270 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:10.157-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:38.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38258"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" test_ref="oval:org.mitre.oval:tst:38534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38635"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38709"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38670"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9262" version="5" class="vulnerability">
      <metadata>
        <title>Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416"/>
        <description>Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:38.791-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:27.463-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:28.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9262 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:09.191-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:37.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39096"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39077"/>
            <criterion comment="libxml-devel is earlier than 1:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:38476"/>
            <criterion comment="libxml is earlier than 1:1.8.17-9.3" test_ref="oval:org.mitre.oval:tst:38526"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-15" test_ref="oval:org.mitre.oval:tst:39158"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:39083"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:38887"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.7" test_ref="oval:org.mitre.oval:tst:39128"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:39183"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:38679"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.8" test_ref="oval:org.mitre.oval:tst:39178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9257" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3120"/>
        <description>Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:51.725-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.983-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:28.282-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9257 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:34.879-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:36.892-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.1" test_ref="oval:org.mitre.oval:tst:31818"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.1" test_ref="oval:org.mitre.oval:tst:32386"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9256" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839"/>
        <description>Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:31.549-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.732-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:27.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9256 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:02.715-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:36.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9254" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1797"/>
        <description>Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:35.750-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:26.330-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:27.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9254 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:40.980-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:35.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9248" version="5" class="vulnerability">
      <metadata>
        <title>The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"/>
        <description>The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:48.147-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:25.344-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:26.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9248 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:39.622-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:34.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39033"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:38392"/>
            <criterion comment="httpd is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39071"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39448"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39501"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:38802"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39716"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39551"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38846"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38761"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38385"/>
            <criterion comment="httpd is earlier than 0:2.2.3-22.el5_3.2" test_ref="oval:org.mitre.oval:tst:38816"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9241" version="5" class="vulnerability">
      <metadata>
        <title>nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776"/>
        <description>nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:06.871-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:24.802-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:25.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9241 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:47.218-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:34.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9238" version="5" class="vulnerability">
      <metadata>
        <title>The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1431"/>
        <description>The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:27.164-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:24.129-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:25.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9238 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:57.140-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:33.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gnutls is earlier than 0:1.0.20-3.2.1" test_ref="oval:org.mitre.oval:tst:31862"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-3.2.1" test_ref="oval:org.mitre.oval:tst:31682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9233" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307"/>
        <description>Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:10.304-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:23.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:24.666-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9233 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:38.991-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:32.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38663"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38680"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38674"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38654"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38700"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38368"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38726"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38390"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38547"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38412"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38701"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9231" version="5" class="vulnerability">
      <metadata>
        <title>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1477" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1477"/>
        <description>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:29.236-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:22.827-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9231 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:56.997-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:31.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31531"/>
            <criterion comment="mozilla is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31619"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31225"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31917"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31644"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31625"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31435"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31816"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31450"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31901"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31590"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.5" test_ref="oval:org.mitre.oval:tst:31571"/>
            <criterion comment="mozilla is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31860"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31894"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31245"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31913"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.5" test_ref="oval:org.mitre.oval:tst:31692"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31986"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31365"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31868"/>
            <criterion comment="firefox is earlier than 0:1.0.4-1.4.1" test_ref="oval:org.mitre.oval:tst:31311"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:30985"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.4.1" test_ref="oval:org.mitre.oval:tst:31723"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9214" version="5" class="vulnerability">
      <metadata>
        <title>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0115"/>
        <description>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:06.750-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:22.592-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:23.648-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9214 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:46.094-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:31.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" test_ref="oval:org.mitre.oval:tst:38584"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:38470"/>
            <criterion comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" test_ref="oval:org.mitre.oval:tst:38587"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9191" version="5" class="vulnerability">
      <metadata>
        <title>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813"/>
        <description>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:53.942-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:19.625-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:20.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9191 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:10.096-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:27.204-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39162"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39589"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39603"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39658"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39633"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39222"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39493"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39205"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9185" version="5" class="vulnerability">
      <metadata>
        <title>The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0966"/>
        <description>The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:20.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:18.273-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9185 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:46.414-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:26.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el3" test_ref="oval:org.mitre.oval:tst:31686"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el4" test_ref="oval:org.mitre.oval:tst:31403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9184" version="5" class="vulnerability">
      <metadata>
        <title>SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2447"/>
        <description>SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.893-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:18.098-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9184 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:48.479-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:25.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="spamassassin is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:32046"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9175" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3628"/>
        <description>Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:41.723-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:17.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:19.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9175 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:53.256-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:25.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9173" version="5" class="vulnerability">
      <metadata>
        <title>lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4065"/>
        <description>lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:37.943-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:17.481-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:18.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9173 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:42.696-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:24.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35005"/>
            <criterion comment="libvorbis is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35016"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34951"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34625"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:35046"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:34551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9167" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:36.424-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:16.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:18.309-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9167 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:22.574-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:24.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9161" version="5" class="vulnerability">
      <metadata>
        <title>components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355"/>
        <description>components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:54.410-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:15.899-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:17.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9161 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:38.636-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:22.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38173"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38181"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38221"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38323"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38337"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:37355"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38135"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38326"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38186"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38184"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38228"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37943"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37433"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38309"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38278"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9157" version="5" class="vulnerability">
      <metadata>
        <title>jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5014"/>
        <description>jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:56.691-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:15.291-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:16.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9157 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:55.846-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:21.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9155" version="5" class="vulnerability">
      <metadata>
        <title>OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077"/>
        <description>OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:49.407-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:14.877-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:16.177-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9155 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:42.971-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:21.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:38011"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:37149"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.25" test_ref="oval:org.mitre.oval:tst:37990"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.49" test_ref="oval:org.mitre.oval:tst:38150"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:37921"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:38056"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" test_ref="oval:org.mitre.oval:tst:37985"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" test_ref="oval:org.mitre.oval:tst:37743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" test_ref="oval:org.mitre.oval:tst:37259"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37599"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37285"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" test_ref="oval:org.mitre.oval:tst:37906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9151" version="5" class="vulnerability">
      <metadata>
        <title>The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0778"/>
        <description>The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:53.508-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:13.905-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:15.151-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9151 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:07.473-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:20.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9145" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870"/>
        <description>Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:06.177-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:13.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:14.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9145 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:52.306-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:19.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33108"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32394"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-35.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33055"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33223"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33235"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33295"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9142" version="5" class="vulnerability">
      <metadata>
        <title>The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2698"/>
        <description>The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:38.799-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.949-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:14.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9142 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:25.612-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.955-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39011"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38739"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38992"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38800"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39114"/>
            <criterion comment="kernel is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39044"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39194"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38832"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39007"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38642"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38673"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39035"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38510"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38920"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39188"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39065"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39182"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39164"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38624"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39175"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38848"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39017"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38949"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39066"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38199"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39057"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39072"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38868"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39155"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38973"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38459"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9140" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084"/>
        <description>Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:16.367-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.678-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9140 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:00.002-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9124" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1861" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1861"/>
        <description>Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:04.611-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.380-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9124 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:25.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:18.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:37450"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38245"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38284"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38008"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38414"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38395"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38234"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38442"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9118" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2365"/>
        <description>Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:27.474-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:12.134-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:13.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9118 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:09.449-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:17.669-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31966"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32076"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32122"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32035"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9117" version="5" class="vulnerability">
      <metadata>
        <title>Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2446"/>
        <description>Race condition between the kfree_skb and __skb_unlink functions in the socket buffer handling in Linux kernel 2.6.9, and possibly other versions, allows remote attackers to cause a denial of service (crash), as demonstrated using the TCP stress tests from the LTP test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:52.196-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.828-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.961-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9117 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:52.742-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:17.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9111" version="5" class="vulnerability">
      <metadata>
        <title>The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255"/>
        <description>String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:36.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.514-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.631-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9111 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:46.394-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:16.793-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31580"/>
          <criterion comment="mozilla is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31555"/>
          <criterion comment="thunderbird is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31382"/>
          <criterion comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31589"/>
          <criterion comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31583"/>
          <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31421"/>
          <criterion comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31222"/>
          <criterion comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31447"/>
          <criterion comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31579"/>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
          <criterion comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31131"/>
          <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" test_ref="oval:org.mitre.oval:tst:31380"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9108" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3106"/>
        <description>Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:02.087-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:11.257-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9108 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:08.145-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:16.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9106" version="5" class="vulnerability">
      <metadata>
        <title>The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0941"/>
        <description>The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:38.519-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:10.851-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:12.079-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9106 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:31.734-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:15.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31752"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31453"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31739"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31617"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31671"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31138"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" test_ref="oval:org.mitre.oval:tst:31736"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9105" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656"/>
        <description>Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:45.122-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:10.352-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:11.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9105 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:58.154-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:15.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9080" version="5" class="vulnerability">
      <metadata>
        <title>The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3784"/>
        <description>The auto-reap of child processes in Linux kernel 2.6 before 2.6.15 includes processes with ptrace attached, which leads to a dangling ptrace reference and allows local users to cause a denial of service (crash) and gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:36.965-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:10.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9080 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:12.473-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:14.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9079" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2099"/>
        <description>The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:48.408-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:09.219-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:10.353-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9079 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:59.421-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:14.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9076" version="5" class="vulnerability">
      <metadata>
        <title>The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2957"/>
        <description>The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:00.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9076 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:29.130-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:13.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37980"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37625"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37827"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37120"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37969"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38038"/>
            <criterion comment="finch is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:37822"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38119"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el4" test_ref="oval:org.mitre.oval:tst:38052"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38103"/>
            <criterion comment="libpurple is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38090"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37997"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38020"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37865"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37809"/>
            <criterion comment="finch is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37973"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:38050"/>
            <criterion comment="pidgin-docs is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37775"/>
            <criterion comment="pidgin is earlier than 0:2.5.2-6.el5" test_ref="oval:org.mitre.oval:tst:37838"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9071" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1704"/>
        <description>Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:13.252-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.389-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.527-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9071 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:25.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:12.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="elfutils-libelf-devel is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32457"/>
            <criterion comment="binutils is earlier than 0:2.14.90.0.4-39" test_ref="oval:org.mitre.oval:tst:31731"/>
            <criterion comment="elfutils-libelf is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32656"/>
            <criterion comment="elfutils-devel is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32533"/>
            <criterion comment="elfutils is earlier than 0:0.94.1-2" test_ref="oval:org.mitre.oval:tst:32396"/>
            <criterion comment="gdb is earlier than 0:6.3.0.0-1.62" test_ref="oval:org.mitre.oval:tst:29887"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="elfutils-libelf-devel is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32684"/>
            <criterion comment="binutils is earlier than 0:2.15.92.0.2-15" test_ref="oval:org.mitre.oval:tst:31192"/>
            <criterion comment="elfutils-libelf is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:31848"/>
            <criterion comment="elfutils-devel is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32660"/>
            <criterion comment="elfutils is earlier than 0:0.97.1-3" test_ref="oval:org.mitre.oval:tst:32629"/>
            <criterion comment="gdb is earlier than 0:6.3.0.0-1.63" test_ref="oval:org.mitre.oval:tst:32136"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9067" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service (instability or crash) and execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3465"/>
        <description>Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service (instability or crash) and execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:00.520-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:08.120-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:09.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9067 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:13.834-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:12.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9063" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5024"/>
        <description>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:08.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:07.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:08.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9063 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:58.999-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:11.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9053" version="5" class="vulnerability">
      <metadata>
        <title>The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4571"/>
        <description>The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:14.491-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:06.665-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:07.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9053 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:39.340-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:10.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35219"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35593"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35357"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35021"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35284"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35088"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:34595"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35139"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35215"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35555"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35511"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35474"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.4.el5" test_ref="oval:org.mitre.oval:tst:35543"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9048" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6111"/>
        <description>Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:04.609-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:06.367-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:07.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9048 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:23.826-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:10.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9040" version="5" class="vulnerability">
      <metadata>
        <title>The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0135"/>
        <description>The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:47.652-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:06.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9040 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:07.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:09.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9020" version="5" class="vulnerability">
      <metadata>
        <title>The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3145"/>
        <description>The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:47.309-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.610-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:06.232-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9020 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:14.859-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:09.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9005" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373"/>
        <description>Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:52.754-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:05.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:05.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9005 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:29.401-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:08.466-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-3.el3" test_ref="oval:org.mitre.oval:tst:38766"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38580"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38729"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38659"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38675"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38361"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38431"/>
            <criterion comment="finch is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38593"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38640"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38564"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38579"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38686"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38687"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38223"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38606"/>
            <criterion comment="finch is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38749"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38576"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9004" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4484" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4484"/>
        <description>Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:38.944-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:04.556-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:05.178-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9004 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:15.824-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:07.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32928"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32870"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32829"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32485"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32258"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32491"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32860"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32175"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32788"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33059"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32876"/>
            <criterion comment="php is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32754"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33047"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33052"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32964"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32700"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32272"/>
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32985"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32808"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32962"/>
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32483"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8996" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3143"/>
        <description>Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:06.152-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:04.157-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:04.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8996 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:15.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:07.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8994" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0529"/>
        <description>Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:20.926-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:03.719-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:04.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8994 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:53.366-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:06.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8992" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0906"/>
        <description>Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:30.268-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:02.968-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:03.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8992 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:43.245-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:05.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8978" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2361" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2361"/>
        <description>Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:45.717-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:01.661-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:02.694-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8978 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:13.119-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:04.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8968" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0238"/>
        <description>Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:45.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:00.206-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:01.225-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8968 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:51.318-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:02.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33440"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33125"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33421"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33334"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33202"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33265"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33436"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33388"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33424"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33485"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33323"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33367"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33452"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33446"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33301"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33679"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33157"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33463"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33142"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33606"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33009"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33302"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33387"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33013"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33611"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33638"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33048"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33513"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33756"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33355"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33147"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33448"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33749"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33529"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33254"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33659"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33060"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33039"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33271"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33389"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33476"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33477"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33051"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33313"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33511"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32740"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33552"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33490"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33514"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33365"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33599"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33533"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33023"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33160"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33553"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33401"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33480"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33168"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33643"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33451"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33201"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33486"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32762"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33450"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33579"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33544"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33358"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33604"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33212"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33377"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33364"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33111"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33324"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33471"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33420"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33670"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32682"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33543"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33517"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33393"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8966" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1379"/>
        <description>Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:16.195-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:59.257-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:00.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8966 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:48.747-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:18:00.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36946"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36579"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36881"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36895"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36542"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36866"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36934"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36951"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36973"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36756"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36632"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36469"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36368"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36851"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36740"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36985"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36805"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36754"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36734"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36918"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36499"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36402"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36931"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36752"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36976"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36867"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36115"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36794"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36943"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-128.EL" test_ref="oval:org.mitre.oval:tst:36905"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36908"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36685"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36662"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36309"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36944"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36641"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36607"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36651"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36977"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36939"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36385"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36979"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36933"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36742"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36873"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36932"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:35995"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" test_ref="oval:org.mitre.oval:tst:36941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:37018"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36836"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36063"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36029"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36986"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36380"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36055"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" test_ref="oval:org.mitre.oval:tst:36359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8916" version="5" class="vulnerability">
      <metadata>
        <title>The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0063"/>
        <description>The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:11:11.357-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:57.885-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:58.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8916 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:45.662-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:59.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36272"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36493"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36531"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36304"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-68" test_ref="oval:org.mitre.oval:tst:36522"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36541"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36418"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36371"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36482"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" test_ref="oval:org.mitre.oval:tst:36207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36318"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36285"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36069"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36233"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" test_ref="oval:org.mitre.oval:tst:36199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8888" version="5" class="vulnerability">
      <metadata>
        <title>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:34.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:56.979-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:57.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8888 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:44.345-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:57.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8880" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "javascript" sequence, aka "HTML escaped low surrogates bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4066"/>
        <description>Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&amp;#56325ascript" sequence, aka "HTML escaped low surrogates bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:22.936-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:56.240-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:57.063-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8880 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:24.188-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:56.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8872" version="5" class="vulnerability">
      <metadata>
        <title>The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4308"/>
        <description>The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:46.912-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:55.587-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:56.417-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8872 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:02.975-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:55.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35660"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35620"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35663"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35627"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35653"/>
            <criterion comment="kernel is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35769"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35035"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35699"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:34809"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35330"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35339"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35337"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35227"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35043"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35276"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:34448"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35366"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35208"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35326"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.15.el5" test_ref="oval:org.mitre.oval:tst:35345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8833" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2335"/>
        <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.466-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:55.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8833 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:30.953-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:54.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.2" test_ref="oval:org.mitre.oval:tst:31634"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.el4.2" test_ref="oval:org.mitre.oval:tst:32163"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8778" version="5" class="vulnerability">
      <metadata>
        <title>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0176"/>
        <description>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:14:29.507-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:54.071-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:54.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8778 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:58.932-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:53.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31870"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31657"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31642"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31984"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31213"/>
            <criterion comment="kernel is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31839"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31941"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31760"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-32.0.1.EL" test_ref="oval:org.mitre.oval:tst:31960"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8768" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1722"/>
        <description>Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:12:44.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:53.535-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:54.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8768 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:09.571-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:53.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36975"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36705"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.53" test_ref="oval:org.mitre.oval:tst:36751"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36818"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36974"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_6.8" test_ref="oval:org.mitre.oval:tst:36816"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36736"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36909"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36512"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.18.el5_2.1" test_ref="oval:org.mitre.oval:tst:36915"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8757" version="5" class="vulnerability">
      <metadata>
        <title>GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0779"/>
        <description>GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:03.340-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:51.570-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:52.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8757 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:29.311-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:51.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8687" version="5" class="vulnerability">
      <metadata>
        <title>A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0729"/>
        <description>A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:13:07.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:51.245-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:52.121-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8687 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:05.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:50.917-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40272"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40483"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40310"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40062"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40096"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39895"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40165"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40131"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40380"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39955"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8584" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981"/>
        <description>Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:10:48.302-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:50.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:51.460-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8584 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:21.857-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:50.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11911" version="5" class="vulnerability">
      <metadata>
        <title>The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1189"/>
        <description>The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:21.594-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:47.293-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:42.258-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11911 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:06.185-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:03.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-38" test_ref="oval:org.mitre.oval:tst:31249"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-38" test_ref="oval:org.mitre.oval:tst:31238"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-38" test_ref="oval:org.mitre.oval:tst:30907"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-38" test_ref="oval:org.mitre.oval:tst:30640"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-38" test_ref="oval:org.mitre.oval:tst:30935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-10" test_ref="oval:org.mitre.oval:tst:30987"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-10" test_ref="oval:org.mitre.oval:tst:31115"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-10" test_ref="oval:org.mitre.oval:tst:31053"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-10" test_ref="oval:org.mitre.oval:tst:31212"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-10" test_ref="oval:org.mitre.oval:tst:31085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11892" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179"/>
        <description>Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:08.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:46.642-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:41.612-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11892 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:44.859-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:02.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11881" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5511"/>
        <description>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:16.954-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:45.975-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:40.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11881 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:39.676-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:01.257-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11868" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0402"/>
        <description>Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:22.906-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:45.292-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:40.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11868 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:40.959-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:00.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="firefox is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11858" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0019"/>
        <description>Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:58.190-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:44.847-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:39.631-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11858 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:58.361-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:00.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdelibs is earlier than 6:3.3.1-3.14" test_ref="oval:org.mitre.oval:tst:31891"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.14" test_ref="oval:org.mitre.oval:tst:32320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11857" version="5" class="vulnerability">
      <metadata>
        <title>Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2446"/>
        <description>Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:04.374-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:44.536-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:39.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11857 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:09.483-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:59.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39929"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39985"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40068"/>
            <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39025"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39228"/>
            <criterion comment="mysql-test is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:38934"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39199"/>
            <criterion comment="mysql-server is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39156"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11855" version="5" class="vulnerability">
      <metadata>
        <title>The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0209"/>
        <description>Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:56.842-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:44.283-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:39.047-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11855 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:45.485-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:59.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31783"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31876"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31592"/>
          <criterion comment="kernel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31714"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31522"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31902"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31817"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11852" version="5" class="vulnerability">
      <metadata>
        <title>The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083"/>
        <description>The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:05.090-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:43.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:37.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11852 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:18.376-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:58.266-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-6.el3" test_ref="oval:org.mitre.oval:tst:39353"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39474"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39423"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39307"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39264"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39332"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39395"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39376"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39381"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39246"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39428"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39414"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39006"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:38683"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39404"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39139"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39341"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11843" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1375"/>
        <description>Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:02.655-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:42.753-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:35.774-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11843 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:19.073-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:56.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36201"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36534"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36373"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36702"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36615"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36490"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36370"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35738"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36249"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:36731"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" test_ref="oval:org.mitre.oval:tst:35733"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36107"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36600"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36529"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36526"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36442"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36238"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36463"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36480"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35876"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36532"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36278"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35724"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36560"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11840" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5794"/>
        <description>Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:59.347-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:42.438-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:35.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11840 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:16.815-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:56.162-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.13" test_ref="oval:org.mitre.oval:tst:33000"/>
            <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.13" test_ref="oval:org.mitre.oval:tst:33245"/>
            <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.13" test_ref="oval:org.mitre.oval:tst:33139"/>
            <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.13" test_ref="oval:org.mitre.oval:tst:33141"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.13" test_ref="oval:org.mitre.oval:tst:32291"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.17.1" test_ref="oval:org.mitre.oval:tst:33097"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17.1" test_ref="oval:org.mitre.oval:tst:32553"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.17.1" test_ref="oval:org.mitre.oval:tst:33044"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.17.1" test_ref="oval:org.mitre.oval:tst:33197"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17.1" test_ref="oval:org.mitre.oval:tst:33036"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11810" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2801"/>
        <description>Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:59.614-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:40.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:32.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11810 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:43.623-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:54.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11808" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1742" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742"/>
        <description>The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:41.602-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:39.895-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:31.772-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11808 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:24.003-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:51.552-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11807" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5078"/>
        <description>Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:33.632-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:39.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:31.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11807 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:09.657-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:50.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.7" test_ref="oval:org.mitre.oval:tst:37704"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-33.el4_7.1" test_ref="oval:org.mitre.oval:tst:37804"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11806" version="5" class="vulnerability">
      <metadata>
        <title>The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3473"/>
        <description>The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:26.986-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:39.412-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:31.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11806 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:03.664-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:49.876-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11804" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1470"/>
        <description>Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:47.280-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:39.171-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:30.971-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11804 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:43.007-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:49.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11803" version="5" class="vulnerability">
      <metadata>
        <title>The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0296"/>
        <description>The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:42.017-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:38.670-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:30.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11803 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:46.954-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:48.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32492"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32486"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32176"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31856"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32548"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31980"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32519"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32478"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31709"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32504"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32502"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:31570"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:31656"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32458"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32216"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32359"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32540"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.3" test_ref="oval:org.mitre.oval:tst:32384"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32647"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11801" version="5" class="vulnerability">
      <metadata>
        <title>The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4333"/>
        <description>The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:27.288-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:38.425-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:30.244-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11801 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:15.851-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:48.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:33011"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:32323"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:33025"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:32974"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11788" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1236" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1236"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:36.009-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:37.072-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:28.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11788 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:29.876-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:46.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11785" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors.  NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6438"/>
        <description>Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors.  NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:14.333-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:36.524-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:27.219-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11785 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:23.854-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:45.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11781" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0064" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064"/>
        <description>Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:20.538-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:35.826-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:26.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11781 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:18.336-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:44.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.24" test_ref="oval:org.mitre.oval:tst:31296"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.5" test_ref="oval:org.mitre.oval:tst:30886"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.24" test_ref="oval:org.mitre.oval:tst:31027"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.24" test_ref="oval:org.mitre.oval:tst:31314"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:31002"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31263"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:31187"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.3" test_ref="oval:org.mitre.oval:tst:31323"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:31257"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31093"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:30716"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-4.3" test_ref="oval:org.mitre.oval:tst:30790"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:30919"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:31111"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.5" test_ref="oval:org.mitre.oval:tst:30331"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:30846"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" test_ref="oval:org.mitre.oval:tst:31305"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31056"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11776" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1007"/>
        <description>Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:52.633-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:35.330-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:26.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11776 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:04:14.654-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:42.704-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gnomemeeting is earlier than 0:0.96.0-5" test_ref="oval:org.mitre.oval:tst:32840"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gnomemeeting is earlier than 0:1.0.2-9" test_ref="oval:org.mitre.oval:tst:33628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11772" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0527"/>
        <description>Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:33.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:34.941-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:25.354-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11772 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:08.012-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:40.769-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11764" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1836" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836"/>
        <description>Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:07.640-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:34.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:24.696-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11764 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:14.613-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:40.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11760" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529"/>
        <description>Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:30.537-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:34.347-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:24.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11760 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:28.521-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:39.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:36760"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:37705"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-13" test_ref="oval:org.mitre.oval:tst:37156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:37713"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:37446"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.5" test_ref="oval:org.mitre.oval:tst:37341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:36730"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:37719"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.6" test_ref="oval:org.mitre.oval:tst:37620"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11754" version="5" class="vulnerability">
      <metadata>
        <title>The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6428"/>
        <description>The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:33.811-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:33.007-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:23.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11754 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:12.235-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:38.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35923"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35665"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36014"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35929"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36011"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35836"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35726"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35715"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35610"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36025"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35789"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35804"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35865"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35793"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35903"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35965"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35922"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35504"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35045"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35914"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35831"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35998"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35975"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36031"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35971"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35711"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35933"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35826"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35753"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35678"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35795"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35934"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35467"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35946"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36116"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35116"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36004"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35483"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36103"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36060"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36074"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35895"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35905"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36012"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35984"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35857"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35681"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35517"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35690"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35399"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35908"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35987"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35861"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11751" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:39.093-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:32.241-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:22.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11751 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:19.395-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:36.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="thunderbird is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32113"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11749" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:38.269-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:31.669-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:21.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11749 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:37.221-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:35.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11747" version="5" class="vulnerability">
      <metadata>
        <title>The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4605"/>
        <description>The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:28.280-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:31.414-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:21.465-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11747 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:19.450-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:35.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11744" version="5" class="vulnerability">
      <metadata>
        <title>The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4881" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4881"/>
        <description>The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:31.673-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:31.099-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:21.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11744 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:18:03.357-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:34.931-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39477"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38676"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39556"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39526"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:38895"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39250"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39485"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39492"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39608"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39456"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.15.EL" test_ref="oval:org.mitre.oval:tst:39277"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11743" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4064" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4064"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:38.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:30.712-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:20.768-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11743 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:17.686-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:34.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11734" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1158"/>
        <description>Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:26.874-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:30.523-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:20.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11734 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:45.379-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:34.147-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11728" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4571"/>
        <description>Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:00.202-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:29.793-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:19.242-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11728 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:06.383-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:33.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11724" version="5" class="vulnerability">
      <metadata>
        <title>Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3257"/>
        <description>Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:22.437-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:29.504-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:18.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11724 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:03.916-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:32.632-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-21.el3" test_ref="oval:org.mitre.oval:tst:33987"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-21.el3" test_ref="oval:org.mitre.oval:tst:34669"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:2.0.2-35.0.4.el4" test_ref="oval:org.mitre.oval:tst:34459"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4" test_ref="oval:org.mitre.oval:tst:33713"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.4.el5" test_ref="oval:org.mitre.oval:tst:34172"/>
            <criterion comment="evolution-data-server is earlier than 0:1.8.0-15.0.4.el5" test_ref="oval:org.mitre.oval:tst:34388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11723" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3274"/>
        <description>Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:50.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:29.119-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:18.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11723 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:29.978-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:32.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11722" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1772"/>
        <description>Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:32.247-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:28.842-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:18.280-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11722 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:00.847-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:31.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-16.2" test_ref="oval:org.mitre.oval:tst:31587"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-22.2" test_ref="oval:org.mitre.oval:tst:31528"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11721" version="5" class="vulnerability">
      <metadata>
        <title>neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2474" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474"/>
        <description>neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:48.734-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:28.602-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:17.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11721 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:55.102-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:30.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38525"/>
            <criterion comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:38882"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="neon is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39020"/>
            <criterion comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" test_ref="oval:org.mitre.oval:tst:39410"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11719" version="5" class="vulnerability">
      <metadata>
        <title>The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0750"/>
        <description>The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:55.823-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:27.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:17.175-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11719 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:39.875-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:29.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11718" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5760"/>
        <description>Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:06.905-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:27.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:16.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11718 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:01.902-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:28.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35795"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35934"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35467"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35946"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36116"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35116"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36004"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35483"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36103"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36060"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36074"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35895"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35905"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36012"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35984"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35857"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35681"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35517"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35690"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35399"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35908"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35987"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35861"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11716" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2052"/>
        <description>Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:44.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:26.783-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:15.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11716 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:38.073-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:27.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.8" test_ref="oval:org.mitre.oval:tst:35717"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.8" test_ref="oval:org.mitre.oval:tst:35704"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.8" test_ref="oval:org.mitre.oval:tst:35616"/>
            <criterion comment="python is earlier than 0:2.2.3-6.8" test_ref="oval:org.mitre.oval:tst:35688"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.4.el4_6.1" test_ref="oval:org.mitre.oval:tst:35282"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.4.el4_6.1" test_ref="oval:org.mitre.oval:tst:35468"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.4.el4_6.1" test_ref="oval:org.mitre.oval:tst:35783"/>
            <criterion comment="python is earlier than 0:2.3.4-14.4.el4_6.1" test_ref="oval:org.mitre.oval:tst:35573"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.4.el4_6.1" test_ref="oval:org.mitre.oval:tst:35259"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11712" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1262"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:04.112-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:26.242-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:14.989-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11712 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:03.817-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:27.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-6.el3" test_ref="oval:org.mitre.oval:tst:33850"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el4" test_ref="oval:org.mitre.oval:tst:33871"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el5" test_ref="oval:org.mitre.oval:tst:34227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11707" version="5" class="vulnerability">
      <metadata>
        <title>nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3623" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3623"/>
        <description>nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:03.533-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:25.407-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:14.165-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11707 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:54.307-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:26.208-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11706" version="5" class="vulnerability">
      <metadata>
        <title>The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989"/>
        <description>The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:24.357-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:24.863-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:13.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11706 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:16.248-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:25.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="thunderbird is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32113"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11704" version="5" class="vulnerability">
      <metadata>
        <title>nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749"/>
        <description>nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:00.640-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:24.375-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:13.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11704 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:18.322-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:24.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11703" version="5" class="vulnerability">
      <metadata>
        <title>The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0525"/>
        <description>The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:18.413-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:23.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:12.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11703 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:20.153-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:24.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31759"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:30948"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31858"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31704"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31679"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31505"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-23.ent" test_ref="oval:org.mitre.oval:tst:31819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31329"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31673"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31737"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31787"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31830"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31383"/>
            <criterion comment="php is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31557"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31541"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31697"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31847"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31523"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31779"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31261"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.6" test_ref="oval:org.mitre.oval:tst:31733"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11702" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:26.485-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:23.575-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:12.256-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11702 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:26.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:23.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11701" version="5" class="vulnerability">
      <metadata>
        <title>The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4813"/>
        <description>The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:37.992-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:23.298-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:11.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11701 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:39.549-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:23.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11695" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2927" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2927"/>
        <description>Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:18.742-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:21.479-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:10.284-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11695 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:13.574-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:22.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-2.el3" test_ref="oval:org.mitre.oval:tst:36472"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-2.el4" test_ref="oval:org.mitre.oval:tst:37369"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37440"/>
            <criterion comment="libpurple is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:36524"/>
            <criterion comment="libpurple-perl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37413"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:36776"/>
            <criterion comment="pidgin-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37512"/>
            <criterion comment="libpurple-devel is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37332"/>
            <criterion comment="finch is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37243"/>
            <criterion comment="pidgin-perl is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37347"/>
            <criterion comment="pidgin is earlier than 0:2.3.1-2.el5_2" test_ref="oval:org.mitre.oval:tst:37098"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11692" version="5" class="vulnerability">
      <metadata>
        <title>ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2661"/>
        <description>ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:14.117-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:21.207-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:09.540-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11692 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:00.828-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:22.215-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32599"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-4.0.rhel3.2" test_ref="oval:org.mitre.oval:tst:32616"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32106"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32605"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32417"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-1.rhel4.4" test_ref="oval:org.mitre.oval:tst:32653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11691" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6497"/>
        <description>Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:27.600-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:20.693-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:08.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11691 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:37.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:21.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11687" version="6" class="vulnerability">
      <metadata>
        <title>ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736"/>
        <description>ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:15.108-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:19.244-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:07.497-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11687 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:16.372-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:19.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39888"/>
            <criterion comment="gcc-java is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39446"/>
            <criterion comment="gcc-g77 is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39829"/>
            <criterion comment="libgcj is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:38894"/>
            <criterion comment="gcc-c++ is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39648"/>
            <criterion comment="libobjc is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39643"/>
            <criterion comment="libstdc++ is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39297"/>
            <criterion comment="libf2c is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39324"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39622"/>
            <criterion comment="gcc-objc is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39791"/>
            <criterion comment="libgnat is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39571"/>
            <criterion comment="libtool-libs is earlier than 0:1.4.3-7" test_ref="oval:org.mitre.oval:tst:39400"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39577"/>
            <criterion comment="gcc-gnat is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39778"/>
            <criterion comment="cpp is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39694"/>
            <criterion comment="libgcj-devel is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39836"/>
            <criterion comment="gcc is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39781"/>
            <criterion comment="libgcc is earlier than 0:3.2.3-60" test_ref="oval:org.mitre.oval:tst:39401"/>
            <criterion comment="libtool is earlier than 0:1.4.3-7" test_ref="oval:org.mitre.oval:tst:39314"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gcc-ppc32 is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39986"/>
            <criterion comment="gcc4-gfortran is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39498"/>
            <criterion comment="gcc-java is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39736"/>
            <criterion comment="gcc-g77 is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39013"/>
            <criterion comment="libgcj is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39960"/>
            <criterion comment="gcc-c++ is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39305"/>
            <criterion comment="libobjc is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39783"/>
            <criterion comment="libgomp is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39491"/>
            <criterion comment="libstdc++ is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39254"/>
            <criterion comment="libgcj4-src is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39874"/>
            <criterion comment="libmudflap-devel is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39639"/>
            <criterion comment="libf2c is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39768"/>
            <criterion comment="gcc-c++-ppc32 is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:38996"/>
            <criterion comment="gcc-objc is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39661"/>
            <criterion comment="gcc4-c++ is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39597"/>
            <criterion comment="libgnat is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39878"/>
            <criterion comment="gcc4 is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39462"/>
            <criterion comment="libtool-libs is earlier than 0:1.5.6-5.el4_8" test_ref="oval:org.mitre.oval:tst:39563"/>
            <criterion comment="libgfortran is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39690"/>
            <criterion comment="gcc4-java is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39853"/>
            <criterion comment="libmudflap is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:38912"/>
            <criterion comment="libstdc++-devel is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39809"/>
            <criterion comment="libgcj4-devel is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39596"/>
            <criterion comment="libgcj-devel is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39567"/>
            <criterion comment="gcc-gnat is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39750"/>
            <criterion comment="cpp is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39937"/>
            <criterion comment="gcc is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:39370"/>
            <criterion comment="libgcc is earlier than 0:3.4.6-11.el4_8.1" test_ref="oval:org.mitre.oval:tst:38965"/>
            <criterion comment="libtool is earlier than 0:1.5.6-5.el4_8" test_ref="oval:org.mitre.oval:tst:39452"/>
            <criterion comment="libgcj4 is earlier than 0:4.1.2-44.EL4_8.1" test_ref="oval:org.mitre.oval:tst:39599"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtool-ltdl-devel is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:39632"/>
            <criterion comment="gcc-gfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39424"/>
            <criterion comment="gcc-java is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39841"/>
            <criterion comment="libgcj is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39777"/>
            <criterion comment="gcc-c++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39779"/>
            <criterion comment="libobjc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39790"/>
            <criterion comment="libstdc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39808"/>
            <criterion comment="libmudflap-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39820"/>
            <criterion comment="gcc-objc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39409"/>
            <criterion comment="libgnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39459"/>
            <criterion comment="libgcj-src is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39523"/>
            <criterion comment="libgfortran is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39689"/>
            <criterion comment="libtool-ltdl is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:39601"/>
            <criterion comment="libmudflap is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39540"/>
            <criterion comment="libstdc++-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39676"/>
            <criterion comment="gcc-objc++ is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39863"/>
            <criterion comment="gcc-gnat is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39537"/>
            <criterion comment="cpp is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39594"/>
            <criterion comment="libgcj-devel is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39638"/>
            <criterion comment="gcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:39483"/>
            <criterion comment="libgcc is earlier than 0:4.1.2-46.el5_4.2" test_ref="oval:org.mitre.oval:tst:38946"/>
            <criterion comment="libtool is earlier than 0:1.5.22-7.el5_4" test_ref="oval:org.mitre.oval:tst:39774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11682" version="5" class="vulnerability">
      <metadata>
        <title>wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1487"/>
        <description>wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:31.480-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:18.468-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:06.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11682 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:02.761-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:19.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11679" version="5" class="vulnerability">
      <metadata>
        <title>The dev_queue_xmit function in Linux kernel 2.6 can fail before calling the local_bh_disable function, which could lead to data corruption and "node lockups."  NOTE: it is not clear whether this issue is exploitable.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6535" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6535"/>
        <description>The dev_queue_xmit function in Linux kernel 2.6 can fail before calling the local_bh_disable function, which could lead to data corruption and "node lockups."  NOTE: it is not clear whether this issue is exploitable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:39.847-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:18.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:06.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11679 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:30.458-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:18.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11674" version="5" class="vulnerability">
      <metadata>
        <title>The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2878" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2878"/>
        <description>The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:45.971-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:17.449-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:05.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11674 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:47.288-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:17.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11672" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3391"/>
        <description>Wireshark 0.99.5 allows remote attackers to cause a denial of service (memory consumption) via a malformed DCP ETSI packet that triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:01.791-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:17.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:05.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11672 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:06.650-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:17.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34755"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34336"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34784"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11670" version="5" class="vulnerability">
      <metadata>
        <title>** DISPUTED **  PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.  NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled.  Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE.  However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2842"/>
        <description>** DISPUTED **  PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.  NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled.  Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE.  However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:49.710-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:16.871-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:04.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11670 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:33.710-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:16.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-7.el3" test_ref="oval:org.mitre.oval:tst:32403"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-7.el4" test_ref="oval:org.mitre.oval:tst:32654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11667" version="5" class="vulnerability">
      <metadata>
        <title>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1739"/>
        <description>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:43.365-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:16.242-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:04.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11667 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:08.263-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:15.922-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-15" test_ref="oval:org.mitre.oval:tst:31831"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-15" test_ref="oval:org.mitre.oval:tst:31900"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-15" test_ref="oval:org.mitre.oval:tst:31493"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-15" test_ref="oval:org.mitre.oval:tst:31810"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-15" test_ref="oval:org.mitre.oval:tst:31915"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-12" test_ref="oval:org.mitre.oval:tst:31946"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-12" test_ref="oval:org.mitre.oval:tst:31973"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-12" test_ref="oval:org.mitre.oval:tst:31596"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-12" test_ref="oval:org.mitre.oval:tst:31676"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-12" test_ref="oval:org.mitre.oval:tst:31629"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11665" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1095"/>
        <description>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:25.946-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:15.675-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:03.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11665 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:16.013-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:14.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11659" version="5" class="vulnerability">
      <metadata>
        <title>fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1740"/>
        <description>fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:31.920-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:15.344-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:02.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11659 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:29.977-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:14.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11658" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4829"/>
        <description>Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:20.962-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:15.109-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:02.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11658 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:10.419-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:13.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.39.1-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40767"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="perl-Archive-Tar is earlier than 1:1.39.1-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11654" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1374"/>
        <description>Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:04.688-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:13.998-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:01.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11654 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:34.243-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:13.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38580"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38729"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38659"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38675"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38361"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38431"/>
            <criterion comment="finch is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38593"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38640"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-2.el4" test_ref="oval:org.mitre.oval:tst:38775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38564"/>
            <criterion comment="libpurple is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38579"/>
            <criterion comment="libpurple-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38686"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38687"/>
            <criterion comment="pidgin-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38223"/>
            <criterion comment="libpurple-devel is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38606"/>
            <criterion comment="finch is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38749"/>
            <criterion comment="pidgin-perl is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38576"/>
            <criterion comment="pidgin is earlier than 0:2.5.5-3.el5" test_ref="oval:org.mitre.oval:tst:38730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11653" version="5" class="vulnerability">
      <metadata>
        <title>The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676"/>
        <description>The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:47.318-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:13.513-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:00.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11653 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:19.997-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:12.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38113"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38107"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38167"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38064"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38380"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37672"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38093"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38127"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38109"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38430"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37764"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38397"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11652" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0419"/>
        <description>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:44.160-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:12.956-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:11:00.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11652 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:47.538-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:11.783-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11647" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0092"/>
        <description>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:26.182-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:12.134-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:59.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11647 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:48.635-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:10.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11646" version="5" class="vulnerability">
      <metadata>
        <title>The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097"/>
        <description>The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:26.715-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:11.858-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:58.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11646 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:42.933-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:10.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11645" version="5" class="vulnerability">
      <metadata>
        <title>pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2471" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2471"/>
        <description>pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:49.333-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:11.537-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:58.700-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11645 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:59.125-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:09.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:9.24-11.30.2" test_ref="oval:org.mitre.oval:tst:32033"/>
            <criterion comment="netpbm-progs is earlier than 0:9.24-11.30.2" test_ref="oval:org.mitre.oval:tst:31648"/>
            <criterion comment="netpbm-devel is earlier than 0:9.24-11.30.2" test_ref="oval:org.mitre.oval:tst:32153"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="netpbm is earlier than 0:10.25-2.EL4.1" test_ref="oval:org.mitre.oval:tst:32140"/>
            <criterion comment="netpbm-progs is earlier than 0:10.25-2.EL4.1" test_ref="oval:org.mitre.oval:tst:32026"/>
            <criterion comment="netpbm-devel is earlier than 0:10.25-2.EL4.1" test_ref="oval:org.mitre.oval:tst:32045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11643" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562"/>
        <description>Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:03.298-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:11.240-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:58.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11643 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:31.273-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:09.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11635" version="5" class="vulnerability">
      <metadata>
        <title>The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4934" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4934"/>
        <description>The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:20.723-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:10.503-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:57.677-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11635 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:49.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:08.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37830"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37968"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37984"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37633"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37352"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38043"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37989"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37908"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37748"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37825"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37732"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38060"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38354"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38313"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38198"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37887"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38174"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38191"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38124"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38417"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37779"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11633" version="5" class="vulnerability">
      <metadata>
        <title>The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1071"/>
        <description>The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:25.709-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:10.208-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:57.304-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11633 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:39.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:07.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11632" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2812"/>
        <description>The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:42.138-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:09.531-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:56.579-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11632 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:02.557-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:06.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37213"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37299"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:36859"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37581"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37124"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37535"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37548"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37152"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37393"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37071"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.EL" test_ref="oval:org.mitre.oval:tst:37024"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36537"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36954"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37079"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36957"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37527"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37262"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37410"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37323"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37508"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37153"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37180"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37188"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11629" version="5" class="vulnerability">
      <metadata>
        <title>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:46.835-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:09.005-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:56.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11629 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:52.669-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:03.274-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11628" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0136"/>
        <description>The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:27.790-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:08.600-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:55.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11628 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:34.359-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:02.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31783"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31876"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31592"/>
            <criterion comment="kernel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31714"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31522"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31902"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31817"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11624" version="5" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1578"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:01.407-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:07.804-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:54.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11624 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:35.123-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:01.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-13.el3" test_ref="oval:org.mitre.oval:tst:38027"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" test_ref="oval:org.mitre.oval:tst:38669"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:37946"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11618" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540.  NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2933"/>
        <description>Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540.  NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:04.440-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:07.250-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:53.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11618 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:30.498-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:15:00.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.5.0.12-0.21.el4" test_ref="oval:org.mitre.oval:tst:36910"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37176"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37474"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37409"/>
            <criterion comment="devhelp is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37522"/>
            <criterion comment="yelp is earlier than 0:2.16.0-20.el5" test_ref="oval:org.mitre.oval:tst:37008"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37414"/>
            <criterion comment="firefox is earlier than 0:3.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37297"/>
            <criterion comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" test_ref="oval:org.mitre.oval:tst:37422"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11615" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of named subpatterns, which triggers a buffer overflow.  NOTE: this issue was originally subsumed by CVE-2006-7224, but that CVE has been REJECTED and split.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4872"/>
        <description>Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of named subpatterns, which triggers a buffer overflow.  NOTE: this issue was originally subsumed by CVE-2006-7224, but that CVE has been REJECTED and split.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:18.843-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:06.253-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:53.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11615 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:47.576-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:59.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:4.5-4.el4_5.4" test_ref="oval:org.mitre.oval:tst:35582"/>
            <criterion comment="pcre is earlier than 0:4.5-4.el4_5.4" test_ref="oval:org.mitre.oval:tst:35771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:6.6-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35756"/>
            <criterion comment="pcre is earlier than 0:6.6-2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35778"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11613" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0784"/>
        <description>Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:24.560-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:05.871-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:52.985-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11613 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:03.159-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:59.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:37988"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:38474"/>
            <criterion comment="systemtap is earlier than 0:0.6.2-2.el4_7" test_ref="oval:org.mitre.oval:tst:38353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:38454"/>
            <criterion comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:38427"/>
            <criterion comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:38210"/>
            <criterion comment="systemtap is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:38233"/>
            <criterion comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" test_ref="oval:org.mitre.oval:tst:38404"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11609" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2702"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:32.686-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:05.101-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:51.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11609 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:12.549-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:58.462-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11607" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4060"/>
        <description>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:02.444-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:04.453-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:51.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11607 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:42.526-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:57.610-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11605" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175"/>
        <description>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:01.628-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:04.233-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:50.858-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11605 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:39.139-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:57.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11604" version="5" class="vulnerability">
      <metadata>
        <title>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321"/>
        <description>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:13.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:03.789-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:50.450-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11604 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:04.121-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:56.151-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-72" test_ref="oval:org.mitre.oval:tst:40084"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-72" test_ref="oval:org.mitre.oval:tst:40256"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-72" test_ref="oval:org.mitre.oval:tst:40497"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-72" test_ref="oval:org.mitre.oval:tst:39569"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-72" test_ref="oval:org.mitre.oval:tst:40456"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-62.el4_8.2" test_ref="oval:org.mitre.oval:tst:40540"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-62.el4_8.2" test_ref="oval:org.mitre.oval:tst:39992"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-62.el4_8.2" test_ref="oval:org.mitre.oval:tst:40545"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-62.el4_8.2" test_ref="oval:org.mitre.oval:tst:40034"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-62.el4_8.2" test_ref="oval:org.mitre.oval:tst:40469"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:40475"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:39803"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:40429"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:40211"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_5.4" test_ref="oval:org.mitre.oval:tst:40461"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11602" version="5" class="vulnerability">
      <metadata>
        <title>Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3655"/>
        <description>Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:23.007-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:03.291-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:49.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11602 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:01.961-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:55.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37606"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37736"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37427"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37760"/>
            <criterion comment="ruby is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37497"/>
            <criterion comment="irb is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:37751"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-13.el3" test_ref="oval:org.mitre.oval:tst:36770"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37462"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37630"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36810"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:36902"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37678"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37674"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" test_ref="oval:org.mitre.oval:tst:37720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37735"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37344"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37697"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37273"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37563"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37438"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37757"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37463"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" test_ref="oval:org.mitre.oval:tst:37172"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11601" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2662"/>
        <description>Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory corruption, a different issue than CVE-2008-2663, CVE-2008-2664, and CVE-2008-2725.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. This CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:44.622-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:02.840-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:49.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11601 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:54.972-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:54.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11600" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2453" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2453"/>
        <description>Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:31.240-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:02.521-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:49.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11600 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:35.627-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:54.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="dia is earlier than 1:0.94-5.7.1" test_ref="oval:org.mitre.oval:tst:32057"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11599" version="5" class="vulnerability">
      <metadata>
        <title>The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4990"/>
        <description>The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protocol requests with crafted size values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:21.837-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:01.706-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:48.456-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11599 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:57.125-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:53.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35923"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35665"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36014"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35929"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36011"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35836"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35726"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35715"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35610"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36025"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35789"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35804"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35865"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35793"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35903"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35965"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35922"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35504"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35045"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35914"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35831"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35998"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35975"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36031"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35971"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35711"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35933"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35826"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35753"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35678"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35795"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35934"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35467"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35946"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36116"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35116"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36004"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35483"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36103"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36060"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36074"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35895"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35905"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36012"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35984"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35857"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35681"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35909"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11598" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1385"/>
        <description>Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:34.836-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:00.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:47.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11598 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:36.962-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:52.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38892"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38222"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:37924"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38847"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38834"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38158"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38513"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38317"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38667"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38814"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38128"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38668"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38883"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38948"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38732"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38969"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38991"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39056"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38817"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:39009"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38672"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" test_ref="oval:org.mitre.oval:tst:38983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11594" version="5" class="vulnerability">
      <metadata>
        <title>The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6284"/>
        <description>The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:51.134-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:10:00.182-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:46.862-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11594 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:23.628-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:51.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-8" test_ref="oval:org.mitre.oval:tst:36021"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-8" test_ref="oval:org.mitre.oval:tst:35780"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-8" test_ref="oval:org.mitre.oval:tst:36040"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-10.1" test_ref="oval:org.mitre.oval:tst:35997"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-10.1" test_ref="oval:org.mitre.oval:tst:36010"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-10.1" test_ref="oval:org.mitre.oval:tst:36108"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.1" test_ref="oval:org.mitre.oval:tst:36081"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.1" test_ref="oval:org.mitre.oval:tst:36005"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.1" test_ref="oval:org.mitre.oval:tst:35956"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11591" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2692"/>
        <description>The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:46.738-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:58.682-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:45.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11591 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:06.342-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:50.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39011"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38739"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38992"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38800"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39114"/>
            <criterion comment="kernel is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39044"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:39194"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38832"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-60.EL" test_ref="oval:org.mitre.oval:tst:38859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39007"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38642"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38673"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39035"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38510"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38920"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39188"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39065"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39182"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:39164"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.9.EL" test_ref="oval:org.mitre.oval:tst:38624"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39175"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38848"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39017"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38949"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39066"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38199"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39057"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39072"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38868"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:39155"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38973"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" test_ref="oval:org.mitre.oval:tst:38459"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11589" version="5" class="vulnerability">
      <metadata>
        <title>Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304"/>
        <description>Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:17.516-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:58.318-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:44.958-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11589 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:31:08.621-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:49.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-68.ent" test_ref="oval:org.mitre.oval:tst:34512"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-68.ent" test_ref="oval:org.mitre.oval:tst:33919"/>
            <criterion comment="httpd is earlier than 0:2.0.46-68.ent" test_ref="oval:org.mitre.oval:tst:34654"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-32.3.ent" test_ref="oval:org.mitre.oval:tst:34770"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-32.3.ent" test_ref="oval:org.mitre.oval:tst:33780"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-32.3.ent" test_ref="oval:org.mitre.oval:tst:34746"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-32.3.ent" test_ref="oval:org.mitre.oval:tst:34650"/>
            <criterion comment="httpd is earlier than 0:2.0.52-32.3.ent" test_ref="oval:org.mitre.oval:tst:34520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34730"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34677"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34399"/>
            <criterion comment="httpd is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11580" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2917" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2917"/>
        <description>Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:40.342-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:57.543-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:43.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11580 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:29:49.195-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:48.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.16" test_ref="oval:org.mitre.oval:tst:32217"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.12" test_ref="oval:org.mitre.oval:tst:32319"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11579" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0016"/>
        <description>Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:29.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:57.074-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:43.434-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11579 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:33.630-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:48.210-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11575" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1286"/>
        <description>Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:21.505-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:56.342-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:42.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11575 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:41.137-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:47.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33776"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33817"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33769"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33528"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33915"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33822"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:34016"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33395"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33957"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33405"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33642"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33024"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33690"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33995"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33892"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33945"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33711"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33857"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33644"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33920"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11572" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015"/>
        <description>Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:16.004-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:55.935-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:42.298-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11572 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:43.732-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:46.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.14.3" test_ref="oval:org.mitre.oval:tst:35741"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.14.3" test_ref="oval:org.mitre.oval:tst:35374"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.14.3" test_ref="oval:org.mitre.oval:tst:35870"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.14.3" test_ref="oval:org.mitre.oval:tst:35978"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.25b-1.el4_6.4" test_ref="oval:org.mitre.oval:tst:35595"/>
            <criterion comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.4" test_ref="oval:org.mitre.oval:tst:35306"/>
            <criterion comment="samba-client is earlier than 0:3.0.25b-1.el4_6.4" test_ref="oval:org.mitre.oval:tst:35481"/>
            <criterion comment="samba is earlier than 0:3.0.25b-1.el4_6.4" test_ref="oval:org.mitre.oval:tst:35294"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.25b-1.el5_1.4" test_ref="oval:org.mitre.oval:tst:35516"/>
            <criterion comment="samba-swat is earlier than 0:3.0.25b-1.el5_1.4" test_ref="oval:org.mitre.oval:tst:35751"/>
            <criterion comment="samba-client is earlier than 0:3.0.25b-1.el5_1.4" test_ref="oval:org.mitre.oval:tst:35112"/>
            <criterion comment="samba is earlier than 0:3.0.25b-1.el5_1.4" test_ref="oval:org.mitre.oval:tst:35677"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11571" version="5" class="vulnerability">
      <metadata>
        <title>arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2729"/>
        <description>arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:52.798-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:55.430-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:41.776-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11571 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:49.537-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:45.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36972"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36412"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36840"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36741"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36936"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36433"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36961"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36949"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36894"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36367"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:37020"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36992"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37039"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36460"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36799"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37005"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:37063"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36981"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36704"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36937"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36703"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36996"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.6.el5" test_ref="oval:org.mitre.oval:tst:36869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11570" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1801"/>
        <description>Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:03.711-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:55.177-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:41.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11570 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:23.248-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:45.530-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="rdesktop is earlier than 0:1.2.0-3" test_ref="oval:org.mitre.oval:tst:37386"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="rdesktop is earlier than 0:1.3.1-9" test_ref="oval:org.mitre.oval:tst:37567"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="rdesktop is earlier than 0:1.4.1-6" test_ref="oval:org.mitre.oval:tst:37100"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11569" version="5" class="vulnerability">
      <metadata>
        <title>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4772"/>
        <description>The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:41.545-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:54.555-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:40.862-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11569 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:26.160-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:44.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tix is earlier than 0:8.1.4-92.8" test_ref="oval:org.mitre.oval:tst:36200"/>
            <criterion comment="tclx is earlier than 0:8.3-92.8" test_ref="oval:org.mitre.oval:tst:35800"/>
            <criterion comment="tcl-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:35961"/>
            <criterion comment="expect-devel is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:36175"/>
            <criterion comment="tcltk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36169"/>
            <criterion comment="itcl is earlier than 0:3.2-92.8" test_ref="oval:org.mitre.oval:tst:35879"/>
            <criterion comment="tcl is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36313"/>
            <criterion comment="expect is earlier than 0:5.38.0-92.8" test_ref="oval:org.mitre.oval:tst:35369"/>
            <criterion comment="tk-devel is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36316"/>
            <criterion comment="tk is earlier than 0:8.3.5-92.8" test_ref="oval:org.mitre.oval:tst:36018"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35948"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35993"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36045"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35949"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36098"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36066"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35942"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36105"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35835"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35597"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35261"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35907"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35319"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35123"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35894"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35781"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36109"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35308"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35856"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36044"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11568" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3986"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:34.714-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:54.298-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:40.584-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11568 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:40.925-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:44.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11567" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956"/>
        <description>Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:22.284-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:53.928-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:40.254-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11567 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:16.713-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:43.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-73.ent" test_ref="oval:org.mitre.oval:tst:38833"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-73.ent" test_ref="oval:org.mitre.oval:tst:38794"/>
            <criterion comment="httpd is earlier than 0:2.0.46-73.ent" test_ref="oval:org.mitre.oval:tst:38826"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38152"/>
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38886"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38344"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38871"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38788"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11565" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6505"/>
        <description>Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:16.339-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:53.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:39.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11565 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:39.393-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:42.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11562" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0718"/>
        <description>Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:47.467-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:52.947-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:39.257-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11562 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:20.607-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:42.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" test_ref="oval:org.mitre.oval:tst:31246"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" test_ref="oval:org.mitre.oval:tst:31854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11556" version="5" class="vulnerability">
      <metadata>
        <title>The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2100"/>
        <description>The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:11.926-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:51.932-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:38.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11556 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:01.439-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:40.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11549" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2953" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2953"/>
        <description>Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:47.802-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:51.537-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:37.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11549 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:55.895-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:40.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37217"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37049"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37429"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37390"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37492"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37521"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37326"/>
            <criterion comment="vim is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:36926"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37520"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37284"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37412"/>
            <criterion comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37218"/>
            <criterion comment="vim is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37405"/>
            <criterion comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37384"/>
            <criterion comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11546" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163"/>
        <description>Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:09.649-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:51.199-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:37.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11546 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:02.789-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:39.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.58" test_ref="oval:org.mitre.oval:tst:38537"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.58" test_ref="oval:org.mitre.oval:tst:38572"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.58" test_ref="oval:org.mitre.oval:tst:38543"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11545" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7226"/>
        <description>Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:20.287-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:50.894-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:37.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11545 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:48.690-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:39.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35615"/>
            <criterion comment="pcre is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35501"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:6.6-2.el5_1.7" test_ref="oval:org.mitre.oval:tst:35251"/>
            <criterion comment="pcre is earlier than 0:6.6-2.el5_1.7" test_ref="oval:org.mitre.oval:tst:35032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11533" version="5" class="vulnerability">
      <metadata>
        <title>Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4019"/>
        <description>Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:22.836-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:48.533-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:34.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11533 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:56.120-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:36.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-2.el3" test_ref="oval:org.mitre.oval:tst:33056"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-2.el4" test_ref="oval:org.mitre.oval:tst:33006"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11530" version="5" class="vulnerability">
      <metadata>
        <title>The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1447"/>
        <description>The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:11.685-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:48.209-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:34.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11530 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:22.892-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:35.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40554"/>
            <criterion comment="perl is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40615"/>
            <criterion comment="perl-CPAN is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:39713"/>
            <criterion comment="perl-CGI is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40065"/>
            <criterion comment="perl-DB_File is earlier than 2:5.8.0-101.EL3" test_ref="oval:org.mitre.oval:tst:40367"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40654"/>
            <criterion comment="perl is earlier than 3:5.8.5-53.el4" test_ref="oval:org.mitre.oval:tst:40417"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:40657"/>
            <criterion comment="perl is earlier than 4:5.8.8-32.el5_5.1" test_ref="oval:org.mitre.oval:tst:39926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11523" version="5" class="vulnerability">
      <metadata>
        <title>ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0494"/>
        <description>ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:52.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:47.228-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:33.255-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11523 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:10:01.385-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:34.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-20.EL3" test_ref="oval:org.mitre.oval:tst:32461"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-20.EL3" test_ref="oval:org.mitre.oval:tst:33429"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-20.EL3" test_ref="oval:org.mitre.oval:tst:33177"/>
            <criterion comment="bind is earlier than 20:9.2.4-20.EL3" test_ref="oval:org.mitre.oval:tst:33126"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-20.EL3" test_ref="oval:org.mitre.oval:tst:33256"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 20:9.2.4-24.EL4" test_ref="oval:org.mitre.oval:tst:32727"/>
            <criterion comment="bind-devel is earlier than 20:9.2.4-24.EL4" test_ref="oval:org.mitre.oval:tst:33357"/>
            <criterion comment="bind-chroot is earlier than 20:9.2.4-24.EL4" test_ref="oval:org.mitre.oval:tst:32675"/>
            <criterion comment="bind is earlier than 20:9.2.4-24.EL4" test_ref="oval:org.mitre.oval:tst:33136"/>
            <criterion comment="bind-libs is earlier than 20:9.2.4-24.EL4" test_ref="oval:org.mitre.oval:tst:33404"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="bind-utils is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33237"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:32565"/>
            <criterion comment="bind-devel is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33314"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:32936"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33164"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33109"/>
            <criterion comment="bind is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33115"/>
            <criterion comment="bind-libs is earlier than 30:9.3.3-8.el5" test_ref="oval:org.mitre.oval:tst:33331"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11520" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310"/>
        <description>Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:11.182-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:46.905-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:32.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11520 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:57.771-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:34.073-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11516" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:56.006-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:46.505-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:32.530-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11516 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:05.929-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:32.292-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.2" test_ref="oval:org.mitre.oval:tst:32462"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.2" test_ref="oval:org.mitre.oval:tst:32283"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.2" test_ref="oval:org.mitre.oval:tst:32535"/>
            <criterion comment="python is earlier than 0:2.2.3-6.2" test_ref="oval:org.mitre.oval:tst:32198"/>
            <criterion comment="pcre-devel is earlier than 0:3.9-10.2" test_ref="oval:org.mitre.oval:tst:31703"/>
            <criterion comment="pcre is earlier than 0:3.9-10.2" test_ref="oval:org.mitre.oval:tst:31925"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.2" test_ref="oval:org.mitre.oval:tst:32327"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.2" test_ref="oval:org.mitre.oval:tst:32549"/>
            <criterion comment="python is earlier than 0:2.3.4-14.2" test_ref="oval:org.mitre.oval:tst:32523"/>
            <criterion comment="pcre-devel is earlier than 0:4.5-3.2.RHEL4" test_ref="oval:org.mitre.oval:tst:32184"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.2" test_ref="oval:org.mitre.oval:tst:31757"/>
            <criterion comment="pcre is earlier than 0:4.5-3.2.RHEL4" test_ref="oval:org.mitre.oval:tst:32077"/>
            <criterion comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" test_ref="oval:org.mitre.oval:tst:31688"/>
            <criterion comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" test_ref="oval:org.mitre.oval:tst:31599"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.2" test_ref="oval:org.mitre.oval:tst:32020"/>
            <criterion comment="exim is earlier than 0:4.43-1.RHEL4.5" test_ref="oval:org.mitre.oval:tst:31631"/>
            <criterion comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" test_ref="oval:org.mitre.oval:tst:31475"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11515" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6110"/>
        <description>Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:08.197-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:46.243-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:32.266-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11515 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:36.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:31.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="htdig-web is earlier than 3:3.2.0b6-4.el4_6" test_ref="oval:org.mitre.oval:tst:35695"/>
            <criterion comment="htdig is earlier than 3:3.2.0b6-4.el4_6" test_ref="oval:org.mitre.oval:tst:35833"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="htdig-web is earlier than 3:3.2.0b6-9.0.1.el5_1" test_ref="oval:org.mitre.oval:tst:35790"/>
            <criterion comment="htdig is earlier than 3:3.2.0b6-9.0.1.el5_1" test_ref="oval:org.mitre.oval:tst:35868"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11510" version="5" class="vulnerability">
      <metadata>
        <title>The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0242"/>
        <description>The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:35.629-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:45.671-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:31.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11510 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:51.909-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:31.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:34921"/>
            <criterion comment="qt is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35117"/>
            <criterion comment="qt-devel is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35255"/>
            <criterion comment="qt-MySQL is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35041"/>
            <criterion comment="qt-ODBC is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:34922"/>
            <criterion comment="qt-designer is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35004"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35085"/>
            <criterion comment="qt is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35125"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:34568"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:34886"/>
            <criterion comment="qt-designer is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35054"/>
            <criterion comment="qt-devel is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35050"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35175"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35165"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35252"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34806"/>
            <criterion comment="qt is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34816"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34466"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35316"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35271"/>
            <criterion comment="qt-designer is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34736"/>
            <criterion comment="qt-devel is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35097"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35149"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35293"/>
            <criterion comment="qt-devel-docs is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35114"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:34994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11508" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6117"/>
        <description>Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:26.630-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:44.930-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:30.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11508 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:04.729-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:30.004-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11507" version="5" class="vulnerability">
      <metadata>
        <title>lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1270"/>
        <description>lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:28.598-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:44.661-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:30.566-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11507 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:24.982-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:29.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:30882"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31108"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.22" test_ref="oval:org.mitre.oval:tst:31170"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:30919"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31056"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11502" version="5" class="vulnerability">
      <metadata>
        <title>The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0591" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0591"/>
        <description>The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:39.701-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:42.844-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:28.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11502 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:19.682-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:28.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32465"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32618"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32497"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32527"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32392"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32719"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32621"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32195"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32628"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32601"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:31936"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32101"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31976"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32564"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32038"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32648"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31768"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32626"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31950"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32604"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32472"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11501" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3801"/>
        <description>Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:37.159-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:42.349-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:28.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11501 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:34.528-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:27.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11500" version="5" class="vulnerability">
      <metadata>
        <title>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2096"/>
        <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:19.287-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:41.955-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:27.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11500 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:34.595-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:27.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="zlib-devel is earlier than 0:1.2.1.2-1.1" test_ref="oval:org.mitre.oval:tst:31702"/>
          <criterion comment="zlib is earlier than 0:1.2.1.2-1.1" test_ref="oval:org.mitre.oval:tst:32083"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11499" version="5" class="vulnerability">
      <metadata>
        <title>The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7176"/>
        <description>The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:57.346-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:41.653-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:27.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11499 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:38.316-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:26.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.13.1-3.2.el4" test_ref="oval:org.mitre.oval:tst:34035"/>
            <criterion comment="sendmail-doc is earlier than 0:8.13.1-3.2.el4" test_ref="oval:org.mitre.oval:tst:33657"/>
            <criterion comment="sendmail-cf is earlier than 0:8.13.1-3.2.el4" test_ref="oval:org.mitre.oval:tst:33996"/>
            <criterion comment="sendmail-devel is earlier than 0:8.13.1-3.2.el4" test_ref="oval:org.mitre.oval:tst:33824"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:40026"/>
            <criterion comment="sendmail-doc is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:40111"/>
            <criterion comment="sendmail-cf is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:40318"/>
            <criterion comment="sendmail-devel is earlier than 0:8.13.8-8.el5" test_ref="oval:org.mitre.oval:tst:39935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11497" version="5" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3459"/>
        <description>Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including a large tdir_count value in the TIFFFetchShortPair function in tif_dirread.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:08.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:41.385-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:27.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11497 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:40.883-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:26.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11496" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5747"/>
        <description>Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:00.103-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:40.825-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:26.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11496 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:03.257-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:25.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32940"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33113"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32275"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33128"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32259"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32596"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33188"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32780"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33131"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33198"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33241"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33268"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33216"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32752"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32536"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32857"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33185"/>
            <criterion comment="firefox is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33140"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33088"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33118"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33171"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32856"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11494" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1459"/>
        <description>Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:18.401-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:40.580-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:26.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11494 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:09.979-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:25.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11489" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2327" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2327"/>
        <description>Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:57.905-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:39.690-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:24.981-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11489 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:55.736-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:24.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-31.el3" test_ref="oval:org.mitre.oval:tst:37373"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-31.el3" test_ref="oval:org.mitre.oval:tst:37614"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37555"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12.el4_7.2" test_ref="oval:org.mitre.oval:tst:37573"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_2.2" test_ref="oval:org.mitre.oval:tst:37340"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_2.2" test_ref="oval:org.mitre.oval:tst:37515"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11487" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1833" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:49.877-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:39.172-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:24.456-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11487 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:35:00.282-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:23.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11486" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3744"/>
        <description>Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) images that trigger heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:41.145-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:38.803-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:24.130-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11486 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:22.428-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:23.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32037"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32699"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32588"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32852"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32383"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32971"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32748"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32946"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32537"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11485" version="5" class="vulnerability">
      <metadata>
        <title>libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing br sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0420"/>
        <description>libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing &lt;br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:20.906-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:38.385-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:23.651-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11485 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:56.335-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:22.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11483" version="5" class="vulnerability">
      <metadata>
        <title>pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1716"/>
        <description>pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:53.432-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:37.779-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:23.001-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11483 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:29.341-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:21.777-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pam-devel is earlier than 0:0.75-72" test_ref="oval:org.mitre.oval:tst:34483"/>
            <criterion comment="pam is earlier than 0:0.75-72" test_ref="oval:org.mitre.oval:tst:34274"/>
            <criterion comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.6" test_ref="oval:org.mitre.oval:tst:34392"/>
            <criterion comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.6" test_ref="oval:org.mitre.oval:tst:34405"/>
            <criterion comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.6" test_ref="oval:org.mitre.oval:tst:33947"/>
            <criterion comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.6" test_ref="oval:org.mitre.oval:tst:34263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pam-devel is earlier than 0:0.77-66.23" test_ref="oval:org.mitre.oval:tst:34850"/>
            <criterion comment="pam is earlier than 0:0.77-66.23" test_ref="oval:org.mitre.oval:tst:34954"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pam-devel is earlier than 0:0.99.6.2-3.26.el5" test_ref="oval:org.mitre.oval:tst:34670"/>
            <criterion comment="pam is earlier than 0:0.99.6.2-3.26.el5" test_ref="oval:org.mitre.oval:tst:34359"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11482" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the Window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5334" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5334"/>
        <description>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the Window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:13.871-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:37.252-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:22.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11482 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:26.559-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:21.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11481" version="5" class="vulnerability">
      <metadata>
        <title>The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3389"/>
        <description>The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:33.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:36.742-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:21.962-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11481 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:09.701-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:20.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32105"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32433"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32429"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32322"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32301"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32253"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32050"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32261"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32003"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32346"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32114"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32325"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32420"/>
            <criterion comment="php is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32337"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32287"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32016"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32405"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32397"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32321"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32207"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:31926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11479" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF file with a large code_size value, a similar issue to CVE-2006-4484.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1373"/>
        <description>Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF file with a large code_size value, a similar issue to CVE-2006-4484.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:31.547-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:36.394-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:21.612-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11479 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:00.680-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:19.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36146"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36214"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.52" test_ref="oval:org.mitre.oval:tst:36403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36474"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:35913"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" test_ref="oval:org.mitre.oval:tst:36036"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.6" test_ref="oval:org.mitre.oval:tst:36593"/>
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.6" test_ref="oval:org.mitre.oval:tst:36521"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.14.el5_1.6" test_ref="oval:org.mitre.oval:tst:36179"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.6" test_ref="oval:org.mitre.oval:tst:36567"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11477" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2103"/>
        <description>Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:44.885-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:35.943-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:21.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11477 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:39.764-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:19.264-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el3.3" test_ref="oval:org.mitre.oval:tst:32063"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.3.1-0.el4.3" test_ref="oval:org.mitre.oval:tst:31738"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11476" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3631"/>
        <description>Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:09.899-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:35.698-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:20.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11476 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:30.727-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:18.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11473" version="5" class="vulnerability">
      <metadata>
        <title>fs/exec.c in Linux 2.6, when one thread is tracing another thread that shares the same memory map, might allow local users to cause a denial of service (deadlock) by forcing a core dump when the traced thread is in the TASK_TRACED state.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3107"/>
        <description>fs/exec.c in Linux 2.6, when one thread is tracing another thread that shares the same memory map, might allow local users to cause a denial of service (deadlock) by forcing a core dump when the traced thread is in the TASK_TRACED state.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:19.325-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:34.978-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:20.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11473 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:38.922-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:17.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31783"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31876"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31592"/>
            <criterion comment="kernel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31714"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31522"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31902"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-11.EL" test_ref="oval:org.mitre.oval:tst:31817"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11471" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4068"/>
        <description>Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:56.709-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:34.358-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:19.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11471 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:45.304-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:17.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11470" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0377"/>
        <description>CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:44.957-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:34.129-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:18.818-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11470 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:13.503-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:16.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el3" test_ref="oval:org.mitre.oval:tst:32265"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.6-5.el4" test_ref="oval:org.mitre.oval:tst:32721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11468" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0739"/>
        <description>Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:39.281-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:33.623-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:18.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11468 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:45.677-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:15.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:39543"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40329"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40000"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40032"/>
            <criterion comment="tetex-doc is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40150"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40389"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40303"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11467" version="5" class="vulnerability">
      <metadata>
        <title>mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3357"/>
        <description>mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:52.641-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:33.333-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:17.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11467 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:49.890-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:15.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-56.ent" test_ref="oval:org.mitre.oval:tst:32315"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-56.ent" test_ref="oval:org.mitre.oval:tst:32356"/>
            <criterion comment="httpd is earlier than 0:2.0.46-56.ent" test_ref="oval:org.mitre.oval:tst:32098"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-22.ent" test_ref="oval:org.mitre.oval:tst:32426"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-22.ent" test_ref="oval:org.mitre.oval:tst:31907"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-22.ent" test_ref="oval:org.mitre.oval:tst:31584"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-22.ent" test_ref="oval:org.mitre.oval:tst:32282"/>
            <criterion comment="httpd is earlier than 0:2.0.52-22.ent" test_ref="oval:org.mitre.oval:tst:32132"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11466" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3142"/>
        <description>Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:01.314-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:32.908-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:17.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11466 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:16.225-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:14.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11465" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411"/>
        <description>Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:33.378-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:32.194-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:17.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11465 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:48.249-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:14.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="subversion-devel is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38517"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38702"/>
            <criterion comment="subversion-perl is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:39100"/>
            <criterion comment="subversion is earlier than 0:1.1.4-3.el4_8.2" test_ref="oval:org.mitre.oval:tst:38928"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="subversion-ruby is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:38842"/>
            <criterion comment="subversion-javahl is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:38861"/>
            <criterion comment="subversion-devel is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:38978"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:38984"/>
            <criterion comment="subversion-perl is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:39069"/>
            <criterion comment="subversion is earlier than 0:1.4.2-4.el5_3.1" test_ref="oval:org.mitre.oval:tst:38651"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11464" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3639"/>
        <description>Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:50.274-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:31.687-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:16.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11464 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:31.596-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:13.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37294"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37772"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.54" test_ref="oval:org.mitre.oval:tst:37394"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37546"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37714"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" test_ref="oval:org.mitre.oval:tst:37699"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37215"/>
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37378"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37794"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" test_ref="oval:org.mitre.oval:tst:37702"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11463" version="5" class="vulnerability">
      <metadata>
        <title>Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1856"/>
        <description>Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:25.917-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:31.425-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:16.591-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11463 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:17.997-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:13.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="vixie-cron is earlier than 0:4.1-19.EL3" test_ref="oval:org.mitre.oval:tst:33912"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="vixie-cron is earlier than 4:4.1-47.EL4" test_ref="oval:org.mitre.oval:tst:33630"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="vixie-cron is earlier than 4:4.1-70.el5" test_ref="oval:org.mitre.oval:tst:34161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11459" version="5" class="vulnerability">
      <metadata>
        <title>XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1859" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1859"/>
        <description>XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:22.739-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:30.869-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:15.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11459 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:23.190-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:12.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xscreensaver is earlier than 1:4.10-21.el3" test_ref="oval:org.mitre.oval:tst:33474"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="xscreensaver is earlier than 1:4.18-5.rhel4.14" test_ref="oval:org.mitre.oval:tst:33891"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11457" version="5" class="vulnerability">
      <metadata>
        <title>The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6285"/>
        <description>The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:45.683-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:30.449-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:15.466-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11457 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:32.123-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:11.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="autofs5 is earlier than 1:5.0.1-0.rc2.55.el4_6.2" test_ref="oval:org.mitre.oval:tst:35487"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="autofs is earlier than 1:5.0.1-0.rc2.55.el5.2" test_ref="oval:org.mitre.oval:tst:35727"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11456" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4456"/>
        <description>Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:41.009-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:30.148-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:15.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11456 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:41.260-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:11.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39929"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39985"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40068"/>
            <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39025"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39228"/>
            <criterion comment="mysql-test is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:38934"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39199"/>
            <criterion comment="mysql-server is earlier than 0:5.0.77-3.el5" test_ref="oval:org.mitre.oval:tst:39156"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11455" version="5" class="vulnerability">
      <metadata>
        <title>mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserved kernel page memory, which allows local users to cause a denial of service (OOPS) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3739"/>
        <description>mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserved kernel page memory, which allows local users to cause a denial of service (OOPS) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:57.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:29.509-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:14.502-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11455 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:11.117-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:10.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35660"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35620"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35663"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35627"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35653"/>
            <criterion comment="kernel is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35769"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35035"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:35699"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-53.EL" test_ref="oval:org.mitre.oval:tst:34809"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11454" version="5" class="vulnerability">
      <metadata>
        <title>The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2969" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2969"/>
        <description>The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:02.259-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:29.213-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:14.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11454 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:48.326-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:09.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32376"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32370"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.17" test_ref="oval:org.mitre.oval:tst:32357"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-16.22.4" test_ref="oval:org.mitre.oval:tst:32193"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31576"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:31826"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.4" test_ref="oval:org.mitre.oval:tst:32196"/>
            <criterion comment="openssl096b is earlier than 0:0.9.6b-22.4" test_ref="oval:org.mitre.oval:tst:32241"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11453" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4066"/>
        <description>Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:26.945-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:28.887-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:13.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11453 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:51.949-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:08.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35005"/>
            <criterion comment="libvorbis is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35016"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34951"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34625"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:35046"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:34551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11452" version="5" class="vulnerability">
      <metadata>
        <title>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:46.366-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:28.601-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:13.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11452 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:17.205-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:08.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31786"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31975"/>
            <criterion comment="httpd is earlier than 0:2.0.46-46.2.ent" test_ref="oval:org.mitre.oval:tst:31650"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31790"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31890"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31948"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:31906"/>
            <criterion comment="httpd is earlier than 0:2.0.52-12.1.ent" test_ref="oval:org.mitre.oval:tst:32146"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11450" version="5" class="vulnerability">
      <metadata>
        <title>ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0642"/>
        <description>ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:24.949-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:27.936-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:12.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11450 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:09.106-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:07.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38694"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38591"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38715"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38523"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38864"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38549"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" test_ref="oval:org.mitre.oval:tst:38837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38178"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38751"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38045"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38362"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38133"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38911"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38738"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38574"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:38762"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11449" version="5" class="vulnerability">
      <metadata>
        <title>lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c.  NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3106"/>
        <description>lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c.  NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:08.943-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:27.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:12.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11449 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:47.447-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:07.087-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35005"/>
            <criterion comment="libvorbis is earlier than 1:1.0-8.el3" test_ref="oval:org.mitre.oval:tst:35016"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34951"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-2.el4.5" test_ref="oval:org.mitre.oval:tst:34625"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:35046"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5.0" test_ref="oval:org.mitre.oval:tst:34551"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11448" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2589" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2589"/>
        <description>Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbitrary users via certain data in the SRC attribute of an IMG element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:41.401-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:27.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:11.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11448 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:37.375-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:06.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-6.el3" test_ref="oval:org.mitre.oval:tst:33850"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el4" test_ref="oval:org.mitre.oval:tst:33871"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el5" test_ref="oval:org.mitre.oval:tst:34227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11444" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2922"/>
        <description>Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:34.199-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:26.766-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:11.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11444 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:35.174-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:05.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11443" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5337"/>
        <description>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:00.169-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:26.137-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:10.659-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11443 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:42.239-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:04.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35512"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35540"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35394"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35541"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35553"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35552"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:34924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35155"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" test_ref="oval:org.mitre.oval:tst:35441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35489"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35324"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" test_ref="oval:org.mitre.oval:tst:35240"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35182"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35311"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35454"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.7.el4" test_ref="oval:org.mitre.oval:tst:35398"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35351"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35482"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34790"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:35291"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" test_ref="oval:org.mitre.oval:tst:34577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35262"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-6.el5" test_ref="oval:org.mitre.oval:tst:35202"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-5.el5" test_ref="oval:org.mitre.oval:tst:35177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11442" version="5" class="vulnerability">
      <metadata>
        <title>The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6450"/>
        <description>The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:48.565-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:25.728-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:10.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11442 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:33.996-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:04.349-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11441" version="5" class="vulnerability">
      <metadata>
        <title>Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0746" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0746"/>
        <description>Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:18.276-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:25.535-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:10.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11441 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:27.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:04.040-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.9" test_ref="oval:org.mitre.oval:tst:32530"/>
          <criterion comment="kdegraphics is earlier than 7:3.3.1-3.9" test_ref="oval:org.mitre.oval:tst:32495"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11440" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3193"/>
        <description>Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:43.505-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:25.001-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:09.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11440 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:07.128-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:03.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32490"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:32463"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.34" test_ref="oval:org.mitre.oval:tst:31538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:31551"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.3" test_ref="oval:org.mitre.oval:tst:32230"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32368"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.9" test_ref="oval:org.mitre.oval:tst:32431"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11437" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_mempolicy in an MPOL_BIND operation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4130"/>
        <description>The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_mempolicy in an MPOL_BIND operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:05.736-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:24.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:09.230-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11437 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:46.185-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:02.922-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
          <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11436" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5017"/>
        <description>Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:02.186-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:24.071-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:08.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11436 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:01.656-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:01.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11433" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane.  NOTE: this issue can be leveraged for phishing and other attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2871"/>
        <description>Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane.  NOTE: this issue can be leveraged for phishing and other attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:41.326-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:23.152-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:07.638-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11433 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:17.849-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:01.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34331"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34371"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34445"/>
            <criterion comment="yelp is earlier than 0:2.16.0-15.el5" test_ref="oval:org.mitre.oval:tst:33445"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34323"/>
            <criterion comment="devhelp is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34204"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34162"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:33979"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11431" version="5" class="vulnerability">
      <metadata>
        <title>The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1562"/>
        <description>The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:34.326-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:22.247-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:06.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11431 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:50.478-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:14:00.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34371"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34445"/>
            <criterion comment="yelp is earlier than 0:2.16.0-15.el5" test_ref="oval:org.mitre.oval:tst:33445"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34323"/>
            <criterion comment="devhelp is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34204"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34162"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11425" version="5" class="vulnerability">
      <metadata>
        <title>backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimization."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5540"/>
        <description>backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimization."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:11.954-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:21.124-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:05.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11425 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:07.495-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:58.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33558"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33220"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33285"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33432"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33464"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33104"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33317"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33537"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33539"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33243"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" test_ref="oval:org.mitre.oval:tst:33246"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33442"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33531"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33065"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32982"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33144"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33007"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33534"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33427"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33173"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33069"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:33496"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33181"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33488"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33593"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33121"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33568"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33396"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33603"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32610"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:32997"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.8-1.el5" test_ref="oval:org.mitre.oval:tst:33536"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11424" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1196"/>
        <description>Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:53.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:20.665-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:04.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11424 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:42.666-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:58.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.6.4-8.el4" test_ref="oval:org.mitre.oval:tst:40755"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40435"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40552"/>
            <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40721"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40480"/>
            <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40813"/>
            <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40221"/>
            <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40385"/>
            <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:40828"/>
            <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40814"/>
            <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:40524"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40620"/>
            <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40722"/>
            <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:40273"/>
            <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11423" version="5" class="vulnerability">
      <metadata>
        <title>The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5503" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5503"/>
        <description>The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:51.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:20.225-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:04.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11423 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:22.808-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:57.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11422" version="5" class="vulnerability">
      <metadata>
        <title>OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0239" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0239"/>
        <description>OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:06.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:18.840-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:02.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11422 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:32.472-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:56.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33440"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33125"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" test_ref="oval:org.mitre.oval:tst:33421"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33334"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33202"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33265"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" test_ref="oval:org.mitre.oval:tst:33436"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33388"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33424"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33485"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33323"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33367"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33452"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33446"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33301"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33679"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33157"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33463"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33142"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33606"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33009"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33302"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33387"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33013"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33611"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33638"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33048"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33513"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33756"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33355"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33147"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33448"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33749"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33529"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33254"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33659"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33060"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33039"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33271"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33389"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33476"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33477"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33051"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33313"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33511"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32740"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33552"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33490"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33514"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33365"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33599"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33533"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33023"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33160"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33553"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33401"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33480"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33168"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33643"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33451"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33201"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33486"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32762"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33450"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33579"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33544"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33358"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33604"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33212"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33377"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33364"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33111"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33324"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33471"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33420"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33670"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:32682"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33543"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33517"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33393"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.1" test_ref="oval:org.mitre.oval:tst:33484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11421" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4565"/>
        <description>Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:00.538-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:18.329-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:02.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11421 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:46.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:55.523-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11419" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0611" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0611"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:21.187-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:18.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:02.242-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11419 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:58.150-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:55.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.3-1" test_ref="oval:org.mitre.oval:tst:31595"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11416" version="5" class="vulnerability">
      <metadata>
        <title>The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1173"/>
        <description>The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:35.767-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:17.344-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:01.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11416 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:19.521-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:54.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40810"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40798"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40737"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40705"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40784"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40711"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40801"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40491"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40523"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40665"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.26.EL" test_ref="oval:org.mitre.oval:tst:40648"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40501"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40283"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40807"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40842"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40793"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40732"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40830"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40349"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39978"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:39896"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40791"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.8.1.el5" test_ref="oval:org.mitre.oval:tst:40580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11415" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446"/>
        <description>Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:35.221-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:16.918-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:01.001-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11415 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:30.070-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:53.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.13.2" test_ref="oval:org.mitre.oval:tst:34247"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.13.2" test_ref="oval:org.mitre.oval:tst:33727"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.13.2" test_ref="oval:org.mitre.oval:tst:33913"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.13.2" test_ref="oval:org.mitre.oval:tst:33962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.10-1.4E.12.2" test_ref="oval:org.mitre.oval:tst:34121"/>
            <criterion comment="samba-swat is earlier than 0:3.0.10-1.4E.12.2" test_ref="oval:org.mitre.oval:tst:34199"/>
            <criterion comment="samba-client is earlier than 0:3.0.10-1.4E.12.2" test_ref="oval:org.mitre.oval:tst:34107"/>
            <criterion comment="samba is earlier than 0:3.0.10-1.4E.12.2" test_ref="oval:org.mitre.oval:tst:34156"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.23c-2.el5.2.0.2" test_ref="oval:org.mitre.oval:tst:34266"/>
            <criterion comment="samba-swat is earlier than 0:3.0.23c-2.el5.2.0.2" test_ref="oval:org.mitre.oval:tst:33487"/>
            <criterion comment="samba-client is earlier than 0:3.0.23c-2.el5.2.0.2" test_ref="oval:org.mitre.oval:tst:33303"/>
            <criterion comment="samba is earlier than 0:3.0.23c-2.el5.2.0.2" test_ref="oval:org.mitre.oval:tst:34130"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11410" version="5" class="vulnerability">
      <metadata>
        <title>A regression error in the restore_all code path of the 4/4GB split support for non-hugemem Linux kernels on Red Hat Linux Desktop and Enterprise Linux 4 allows local users to cause a denial of service (panic) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2932"/>
        <description>A regression error in the restore_all code path of the 4/4GB split support for non-hugemem Linux kernels on Red Hat Linux Desktop and Enterprise Linux 4 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:14.510-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:16.273-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:00.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11410 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:41.548-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:52.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11408" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5748"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:58.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:14.761-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:58.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11408 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:09.436-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:51.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32940"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33113"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32275"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33128"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32259"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32596"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33188"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:32780"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33131"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el3" test_ref="oval:org.mitre.oval:tst:33022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33198"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33241"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33268"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33216"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32752"/>
            <criterion comment="seamonkey is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32536"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32857"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.5.el4" test_ref="oval:org.mitre.oval:tst:33185"/>
            <criterion comment="firefox is earlier than 0:1.5.0.8-0.1.el4" test_ref="oval:org.mitre.oval:tst:33140"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33088"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33118"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33171"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:32856"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.6-0.1.el4" test_ref="oval:org.mitre.oval:tst:33214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11407" version="5" class="vulnerability">
      <metadata>
        <title>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149"/>
        <description>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:52.110-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:14.250-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:58.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11407 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:46.940-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:51.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:30819"/>
            <criterion comment="mozilla is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31515"/>
            <criterion comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31278"/>
            <criterion comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31465"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31606"/>
            <criterion comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31480"/>
            <criterion comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31417"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31313"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31469"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31598"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="thunderbird is earlier than 0:1.0-1.1.EL4" test_ref="oval:org.mitre.oval:tst:31099"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11403" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modified after it has been read but before it has been locked.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3110"/>
        <description>Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modified after it has been read but before it has been locked.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:59.360-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:13.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:57.304-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11403 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:38.984-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:50.075-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11402" version="5" class="vulnerability">
      <metadata>
        <title>inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1849"/>
        <description>inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:59.963-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:12.945-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:57.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11402 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:11.256-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:49.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="zlib-devel is earlier than 0:1.2.1.2-1.2" test_ref="oval:org.mitre.oval:tst:31912"/>
          <criterion comment="zlib is earlier than 0:1.2.1.2-1.2" test_ref="oval:org.mitre.oval:tst:31730"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11396" version="5" class="vulnerability">
      <metadata>
        <title>The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652"/>
        <description>The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:03.909-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:11.823-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:55.722-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11396 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:15.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:48.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11395" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3804"/>
        <description>Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:38.659-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:11.203-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:55.230-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11395 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:28.133-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:47.696-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11394" version="5" class="vulnerability">
      <metadata>
        <title>The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2872"/>
        <description>The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:30.637-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:10.891-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:54.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11394 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:49.103-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:47.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11393" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1950" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1950"/>
        <description>Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:02.740-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:10.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:54.638-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11393 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:50.726-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:46.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36194"/>
            <criterion comment="gnutls-devel is earlier than 0:1.0.20-4.el4_6" test_ref="oval:org.mitre.oval:tst:36609"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnutls is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36294"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:35940"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-3.el5_1" test_ref="oval:org.mitre.oval:tst:36811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11391" version="5" class="vulnerability">
      <metadata>
        <title>The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0169"/>
        <description>The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:37.711-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:09.723-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:53.703-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11391 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:33.863-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:45.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39910"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40282"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40001"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40160"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39327"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39963"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39749"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40277"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39865"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40145"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40087"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40185"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40258"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40130"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40147"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40264"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11390" version="5" class="vulnerability">
      <metadata>
        <title>The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5925" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5925"/>
        <description>The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:05.328-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:09.414-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:53.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11390 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:12.097-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:45.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35955"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35904"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35382"/>
            <criterion comment="mysql-server is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.22-2.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35902"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.22-2.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35707"/>
            <criterion comment="mysql-test is earlier than 0:5.0.22-2.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35488"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.22-2.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35838"/>
            <criterion comment="mysql-server is earlier than 0:5.0.22-2.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35066"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11389" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2026"/>
        <description>Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:26.803-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:09.168-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:53.136-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11389 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:51.157-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:44.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11387" version="5" class="vulnerability">
      <metadata>
        <title>Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5051"/>
        <description>Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:09.505-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:08.514-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:52.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11387 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:57.937-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:43.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.12" test_ref="oval:org.mitre.oval:tst:33091"/>
            <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.12" test_ref="oval:org.mitre.oval:tst:33089"/>
            <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.12" test_ref="oval:org.mitre.oval:tst:32651"/>
            <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.12" test_ref="oval:org.mitre.oval:tst:32799"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.12" test_ref="oval:org.mitre.oval:tst:32173"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.17" test_ref="oval:org.mitre.oval:tst:32994"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17" test_ref="oval:org.mitre.oval:tst:32813"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.17" test_ref="oval:org.mitre.oval:tst:33151"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.17" test_ref="oval:org.mitre.oval:tst:33040"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17" test_ref="oval:org.mitre.oval:tst:33167"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11386" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0031"/>
        <description>Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:38.238-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:07.982-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:51.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11386 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:12.229-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:43.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:37961"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38169"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38048"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38359"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38449"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38416"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38237"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:37920"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38429"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38339"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.17.EL" test_ref="oval:org.mitre.oval:tst:38155"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37732"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38060"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38354"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38313"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38198"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37887"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38174"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38191"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38124"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38417"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37779"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11385" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587"/>
        <description>Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:45.842-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:07.627-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:51.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11385 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:43.752-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:42.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution is earlier than 0:1.4.5-25.el3" test_ref="oval:org.mitre.oval:tst:38285"/>
            <criterion comment="evolution-devel is earlier than 0:1.4.5-25.el3" test_ref="oval:org.mitre.oval:tst:38422"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38140"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38464"/>
            <criterion comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" test_ref="oval:org.mitre.oval:tst:38477"/>
            <criterion comment="evolution is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38489"/>
            <criterion comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" test_ref="oval:org.mitre.oval:tst:38193"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" test_ref="oval:org.mitre.oval:tst:38059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:38514"/>
            <criterion comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37983"/>
            <criterion comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" test_ref="oval:org.mitre.oval:tst:37891"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11383" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4065"/>
        <description>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:00.449-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:06.656-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:50.610-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11383 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:23.810-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:40.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-16.el4" test_ref="oval:org.mitre.oval:tst:37634"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.17-1.el5" test_ref="oval:org.mitre.oval:tst:37230"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11382" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.  NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox.  Also, it has been independently reported that Netscape 8.1 does not have this issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134"/>
        <description>Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.  NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox.  Also, it has been independently reported that Netscape 8.1 does not have this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:44.003-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:06.197-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:50.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11382 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:29.602-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:40.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32492"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32486"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32176"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31856"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32548"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31980"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32519"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:32478"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31709"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32504"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32502"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:31570"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:31656"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32458"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32216"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32359"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32540"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.3" test_ref="oval:org.mitre.oval:tst:32384"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32647"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.2" test_ref="oval:org.mitre.oval:tst:32454"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11381" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007"/>
        <description>Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:01.737-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:05.914-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:49.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11381 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:39.522-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:39.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11379" version="5" class="vulnerability">
      <metadata>
        <title>libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703"/>
        <description>libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:40.168-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:05.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:49.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11379 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:31.889-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:38.745-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="pidgin is earlier than 0:1.5.1-6.el3" test_ref="oval:org.mitre.oval:tst:39353"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39474"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39423"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39307"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39264"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39332"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39395"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39376"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39381"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39246"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39428"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39414"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39006"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:38683"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39404"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39139"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39341"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11378" version="5" class="vulnerability">
      <metadata>
        <title>The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1070"/>
        <description>The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:08.857-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:04.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:48.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11378 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:40.456-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:38.251-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11377" version="5" class="vulnerability">
      <metadata>
        <title>The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399"/>
        <description>Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:21.170-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:04.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:48.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11377 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:18.928-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:37.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:30819"/>
            <criterion comment="mozilla is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31515"/>
            <criterion comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31278"/>
            <criterion comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31465"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31606"/>
            <criterion comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31480"/>
            <criterion comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31417"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31313"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31469"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31598"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="thunderbird is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31382"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="firefox is earlier than 0:1.0.2-1.4.1" test_ref="oval:org.mitre.oval:tst:31302"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11376" version="5" class="vulnerability">
      <metadata>
        <title>The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error.  NOTE: this issue is due to an incorrect fix for CVE-2007-6239.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1612" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1612"/>
        <description>The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error.  NOTE: this issue is due to an incorrect fix for CVE-2007-6239.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:59.682-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:04.113-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:47.994-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11376 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:38.730-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:37.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 0:2.5.STABLE3-9.3E" test_ref="oval:org.mitre.oval:tst:36413"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 0:2.5.STABLE14-1.4E.el4_6.2" test_ref="oval:org.mitre.oval:tst:36396"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squid is earlier than 0:2.6.STABLE6-5.el5_1.3" test_ref="oval:org.mitre.oval:tst:36064"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11374" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6121"/>
        <description>Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:06.949-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:03.416-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:47.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11374 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:47.691-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:36.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11373" version="5" class="vulnerability">
      <metadata>
        <title>Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0488"/>
        <description>Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:26.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:03.116-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:46.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11373 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:30.726-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:35.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="telnet is earlier than 1:0.17-26.EL3.3" test_ref="oval:org.mitre.oval:tst:31911"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="telnet-server is earlier than 1:0.17-26.EL3.3" test_ref="oval:org.mitre.oval:tst:31044"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="telnet is earlier than 1:0.17-31.EL4.3" test_ref="oval:org.mitre.oval:tst:32031"/>
            <criterion comment="telnet-server is earlier than 1:0.17-31.EL4.3" test_ref="oval:org.mitre.oval:tst:31637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11372" version="5" class="vulnerability">
      <metadata>
        <title>The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169"/>
        <description>The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:16.790-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:02.601-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:46.483-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11372 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:52.141-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:35.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38227"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38356"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38435"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38265"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38483"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38434"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38650"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38352"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38301"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.7-3.el4" test_ref="oval:org.mitre.oval:tst:38636"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38297"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38205"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38583"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38616"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38657"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:38281"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:38646"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:37687"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11370" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2976" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2976"/>
        <description>Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:28.082-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:02.124-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:45.946-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11370 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:19.288-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:34.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32203"/>
            <criterion comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32393"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" test_ref="oval:org.mitre.oval:tst:32388"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32239"/>
            <criterion comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" test_ref="oval:org.mitre.oval:tst:32331"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11368" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044"/>
        <description>Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:31.118-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:01.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:45.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11368 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:40.664-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:33.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38227"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38356"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38435"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38265"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38483"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38434"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38650"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38352"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.36.el3" test_ref="oval:org.mitre.oval:tst:38301"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.7-3.el4" test_ref="oval:org.mitre.oval:tst:38636"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38297"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38205"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38583"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38616"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38657"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-40.el4" test_ref="oval:org.mitre.oval:tst:38632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:38281"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:38646"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-3.el5" test_ref="oval:org.mitre.oval:tst:37687"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11365" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:07.451-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:00.096-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:43.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11365 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:27.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:32.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39378"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39359"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39036"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39270"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39397"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39118"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:38466"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" test_ref="oval:org.mitre.oval:tst:39389"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39088"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39081"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" test_ref="oval:org.mitre.oval:tst:39351"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:38976"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el4" test_ref="oval:org.mitre.oval:tst:39195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39181"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39364"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" test_ref="oval:org.mitre.oval:tst:39293"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39208"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39001"/>
            <criterion comment="nspr is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39223"/>
            <criterion comment="firefox is earlier than 0:3.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39097"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" test_ref="oval:org.mitre.oval:tst:39150"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" test_ref="oval:org.mitre.oval:tst:39206"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11364" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0417"/>
        <description>Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:02.574-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:59.857-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:43.539-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11364 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:48.835-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:31.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11361" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2366"/>
        <description>Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:11.050-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:59.583-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:43.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11361 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:34.436-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:31.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37041"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37101"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-42.2.0.EL3" test_ref="oval:org.mitre.oval:tst:37231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37258"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37327"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:36748"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.5.EL4" test_ref="oval:org.mitre.oval:tst:37002"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11356" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5016"/>
        <description>The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:05.842-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:58.300-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:41.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11356 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:48.383-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:29.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11355" version="5" class="vulnerability">
      <metadata>
        <title>The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3403"/>
        <description>The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:55.581-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:57.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:41.575-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11355 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:52.245-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:29.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.10" test_ref="oval:org.mitre.oval:tst:32912"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.10" test_ref="oval:org.mitre.oval:tst:32281"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.10" test_ref="oval:org.mitre.oval:tst:32746"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.10" test_ref="oval:org.mitre.oval:tst:32584"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.10-1.4E.6.2" test_ref="oval:org.mitre.oval:tst:32794"/>
            <criterion comment="samba-swat is earlier than 0:3.0.10-1.4E.6.2" test_ref="oval:org.mitre.oval:tst:32921"/>
            <criterion comment="samba-client is earlier than 0:3.0.10-1.4E.6.2" test_ref="oval:org.mitre.oval:tst:32338"/>
            <criterion comment="samba is earlier than 0:3.0.10-1.4E.6.2" test_ref="oval:org.mitre.oval:tst:32826"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11351" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5285"/>
        <description>Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:07.927-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:57.210-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:40.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11351 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:53.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:27.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11350" version="5" class="vulnerability">
      <metadata>
        <title>Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS dissectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3630"/>
        <description>Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:49.270-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:56.891-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:40.438-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11350 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:46.500-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:27.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11348" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1458" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1458"/>
        <description>Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:41.442-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:56.416-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:39.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11348 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:27.735-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:26.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11347" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3746" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3746"/>
        <description>Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:36.638-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:56.200-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:39.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11347 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:22.767-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:26.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.1-17" test_ref="oval:org.mitre.oval:tst:32266"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.6-6" test_ref="oval:org.mitre.oval:tst:32119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11346" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3848"/>
        <description>Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:56.225-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:55.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:39.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11346 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:34.944-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:25.493-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11344" version="5" class="vulnerability">
      <metadata>
        <title>Buffer underflow in the ibwdt_ioctl function in drivers/watchdog/ib700wdt.c in the Linux kernel before 2.6.28-rc1 might allow local users to have an unknown impact via a certain /dev/watchdog WDIOC_SETTIMEOUT IOCTL call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5702"/>
        <description>Buffer underflow in the ibwdt_ioctl function in drivers/watchdog/ib700wdt.c in the Linux kernel before 2.6.28-rc1 might allow local users to have an unknown impact via a certain /dev/watchdog WDIOC_SETTIMEOUT IOCTL call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:21.653-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:54.224-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:37.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11344 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:49.331-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:23.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37830"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37968"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37984"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37633"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37352"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38043"/>
          <criterion comment="kernel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37989"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37908"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37748"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37825"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11342" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0456"/>
        <description>Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:35.603-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:53.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:37.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11342 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:33.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:22.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-EL3.1" test_ref="oval:org.mitre.oval:tst:33506"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-EL3.1" test_ref="oval:org.mitre.oval:tst:33535"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-EL4.1" test_ref="oval:org.mitre.oval:tst:33380"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-EL4.1" test_ref="oval:org.mitre.oval:tst:33530"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-1.el5" test_ref="oval:org.mitre.oval:tst:33509"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-1.el5" test_ref="oval:org.mitre.oval:tst:33591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11341" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1993"/>
        <description>Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:51.982-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:53.401-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:36.873-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11341 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:03.606-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:22.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sudo is earlier than 0:1.6.7p5-1.1" test_ref="oval:org.mitre.oval:tst:31628"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sudo is earlier than 0:1.6.7p5-30.1.1" test_ref="oval:org.mitre.oval:tst:31653"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11339" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0337"/>
        <description>Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:43.255-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:52.881-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:36.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11339 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:10.963-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:21.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" test_ref="oval:org.mitre.oval:tst:30929"/>
          <criterion comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" test_ref="oval:org.mitre.oval:tst:31211"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11338" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2199"/>
        <description>Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:57.430-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:52.600-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:36.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11338 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:30.895-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:21.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32211"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32773"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32763"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32657"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32835"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11336" version="5" class="vulnerability">
      <metadata>
        <title>The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2451"/>
        <description>The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:24.344-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:51.999-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:35.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11336 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:27.506-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:20.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:31895"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32477"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32641"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32569"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:31838"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32186"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32797"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32539"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.2.EL" test_ref="oval:org.mitre.oval:tst:32419"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11334" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2267"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:32.128-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:51.280-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:34.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11334 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:30.496-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:19.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32142"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32131"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32154"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32001"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32171"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32162"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31782"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32041"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32004"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32120"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31633"/>
            <criterion comment="mozilla is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31837"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32100"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31821"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31904"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.6" test_ref="oval:org.mitre.oval:tst:31814"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31951"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31554"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32149"/>
            <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:31998"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" test_ref="oval:org.mitre.oval:tst:32061"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11332" version="5" class="vulnerability">
      <metadata>
        <title>The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3180"/>
        <description>The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:39.512-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:50.590-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:34.178-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11332 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:27.983-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:18.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11331" version="5" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0777"/>
        <description>The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:45.140-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:49.931-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:33.491-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11331 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:10.778-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:18.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11327" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1864"/>
        <description>Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:28.349-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:48.942-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:32.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11327 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:21.152-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:16.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
            <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11325" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754"/>
        <description>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:38.831-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:48.365-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:31.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11325 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:14.862-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:15.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:37450"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38245"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38284"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38008"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38414"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38395"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38442"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38234"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-19.el5" test_ref="oval:org.mitre.oval:tst:33863"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-19.el5" test_ref="oval:org.mitre.oval:tst:34305"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-19.el5" test_ref="oval:org.mitre.oval:tst:33877"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11324" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3141"/>
        <description>Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:08.873-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:48.077-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:31.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11324 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:19.559-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:15.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11323" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800"/>
        <description>Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:55.795-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:47.430-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:30.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11323 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:49.330-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:14.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11322" version="5" class="vulnerability">
      <metadata>
        <title>mm/ioremap.c in Linux 2.6 on 64-bit x86 systems allows local users to cause a denial of service or an information leak via an ioremap on a certain memory map that causes the iounmap to perform a lookup of a page that does not exist.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3108"/>
        <description>mm/ioremap.c in Linux 2.6 on 64-bit x86 systems allows local users to cause a denial of service or an information leak via an ioremap on a certain memory map that causes the iounmap to perform a lookup of a page that does not exist.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:25.312-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:47.170-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:30.520-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11322 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:14.760-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:14.019-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11321" version="5" class="vulnerability">
      <metadata>
        <title>Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0907" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0907"/>
        <description>Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:28.725-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:46.434-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:29.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11321 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:55.255-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:13.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11319" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139"/>
        <description>Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:35.776-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:46.190-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:29.492-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11319 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:20.923-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:12.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11318" version="5" class="vulnerability">
      <metadata>
        <title>The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2444" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2444"/>
        <description>The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:25.828-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:45.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:29.055-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11318 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:46.131-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:12.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32576"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32814"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32958"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32801"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32865"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32880"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32747"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32200"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.2.EL" test_ref="oval:org.mitre.oval:tst:32838"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11317" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2706"/>
        <description>Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:44.795-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:45.241-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:28.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11317 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:53.822-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:11.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11316" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2939"/>
        <description>Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:06.880-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:44.807-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:28.125-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11316 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:52.378-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:10.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37941"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37561"/>
            <criterion comment="httpd is earlier than 0:2.0.46-71.ent" test_ref="oval:org.mitre.oval:tst:37595"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37897"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37670"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37862"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37679"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.2" test_ref="oval:org.mitre.oval:tst:37575"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37895"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37730"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:36990"/>
            <criterion comment="httpd is earlier than 0:2.2.3-11.el5_2.4" test_ref="oval:org.mitre.oval:tst:37803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11314" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771"/>
        <description>The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:53.900-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:44.325-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:27.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11314 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:02.123-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:09.892-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11313" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1282"/>
        <description>Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:25.307-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:43.771-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:26.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11313 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:19.242-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:09.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11311" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5935"/>
        <description>Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:59.422-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:43.232-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:26.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11311 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:49.957-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:08.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:39543"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40329"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40000"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40032"/>
            <criterion comment="tetex-doc is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40150"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40389"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40303"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11307" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3627"/>
        <description>Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:01.925-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:42.702-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:25.858-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11307 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:22.885-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:07.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32882"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL3.1" test_ref="oval:org.mitre.oval:tst:32738"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32917"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.2-EL4.1" test_ref="oval:org.mitre.oval:tst:32447"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11305" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2780"/>
        <description>Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:58.684-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:41.960-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:24.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11305 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:24:00.823-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:30:05.395-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:06.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11303" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0455"/>
        <description>Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:42.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:41.181-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:23.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11303 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:13.355-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:05.695-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33776"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33817"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33769"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33528"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33915"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33822"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33405"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33642"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33024"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33995"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33690"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33892"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33711"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33857"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33644"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33920"/>
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:34016"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33957"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33395"/>
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33809"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33997"/>
            <criterion comment="php-common is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33290"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33828"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33441"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:34008"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33560"/>
            <criterion comment="php is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33959"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33722"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33941"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33880"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33878"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33960"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33923"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33551"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33939"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33626"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:33770"/>
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-11.el5" test_ref="oval:org.mitre.oval:tst:34005"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11302" version="5" class="vulnerability">
      <metadata>
        <title>vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2368"/>
        <description>vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:03.905-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:40.830-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:23.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11302 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:24:01.468-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:05.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.4" test_ref="oval:org.mitre.oval:tst:31943"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.4" test_ref="oval:org.mitre.oval:tst:31844"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.4" test_ref="oval:org.mitre.oval:tst:32110"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.4" test_ref="oval:org.mitre.oval:tst:31611"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.4" test_ref="oval:org.mitre.oval:tst:31602"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.40E.7" test_ref="oval:org.mitre.oval:tst:32111"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.40E.7" test_ref="oval:org.mitre.oval:tst:32128"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.40E.7" test_ref="oval:org.mitre.oval:tst:31668"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.40E.7" test_ref="oval:org.mitre.oval:tst:32143"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.40E.7" test_ref="oval:org.mitre.oval:tst:31994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11301" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3462"/>
        <description>Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:05.478-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:40.370-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:23.239-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11301 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:19:00.859-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:23:59.834-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:04.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11299" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1287"/>
        <description>Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:23.638-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:38.906-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:21.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11299 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:47.531-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:02.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="nasm is earlier than 0:0.98.35-3.EL3" test_ref="oval:org.mitre.oval:tst:31348"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nasm-doc is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31776"/>
            <criterion comment="nasm is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31746"/>
            <criterion comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11298" version="5" class="vulnerability">
      <metadata>
        <title>Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5747"/>
        <description>Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:14.951-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:36.643-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:19.718-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11298 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:16.135-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:13:00.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36006"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35494"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36190"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36501"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35931"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36114"/>
            <criterion comment="openoffice.org2-draw is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36163"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36172"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36000"/>
            <criterion comment="openoffice.org2-base is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36287"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36118"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36384"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36302"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35683"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36473"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36223"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36224"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36154"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36091"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35963"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36083"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36271"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35954"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35495"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36299"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36417"/>
            <criterion comment="openoffice.org2 is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35864"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35957"/>
            <criterion comment="openoffice.org2-impress is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36286"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36345"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36181"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35811"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35640"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36248"/>
            <criterion comment="openoffice.org2-calc is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36212"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36434"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36159"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36411"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36382"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36148"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36144"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36401"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36185"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36254"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36289"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36009"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36216"/>
            <criterion comment="openoffice.org2-testtools is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36498"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36314"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36332"/>
            <criterion comment="openoffice.org2-core is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36253"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35829"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36429"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36073"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35502"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36174"/>
            <criterion comment="openoffice.org2-math is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36366"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36276"/>
            <criterion comment="openoffice.org2-writer is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36057"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36162"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36101"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35841"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36520"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36441"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35845"/>
            <criterion comment="openoffice.org is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36307"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36505"/>
            <criterion comment="openoffice.org-writer is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36145"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36546"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36168"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36283"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36322"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36206"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36244"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36471"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36483"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36328"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35810"/>
            <criterion comment="openoffice.org-javafilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36481"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36465"/>
            <criterion comment="openoffice.org-testtools is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36378"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36013"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36191"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35521"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36257"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35797"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36391"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36398"/>
            <criterion comment="openoffice.org-base is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36329"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36437"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36130"/>
            <criterion comment="openoffice.org-core is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35843"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36220"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36466"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36032"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36187"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36058"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36160"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36457"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36341"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36232"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36089"/>
            <criterion comment="openoffice.org-pyuno is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36514"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36486"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36508"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36507"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36348"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36559"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36282"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36405"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36492"/>
            <criterion comment="openoffice.org-draw is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36369"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36308"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36358"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35561"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36070"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36189"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35657"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36204"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36544"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36218"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36400"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36037"/>
            <criterion comment="openoffice.org-calc is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35732"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36117"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36303"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36306"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35966"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36467"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35570"/>
            <criterion comment="openoffice.org-math is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36376"/>
            <criterion comment="openoffice.org-impress is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36339"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11297" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0143"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:32.846-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:36.120-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:19.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11297 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:21.289-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:59.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11295" version="5" class="vulnerability">
      <metadata>
        <title>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2275"/>
        <description>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:10.895-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:35.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:18.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11295 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:43.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:59.446-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11294" version="5" class="vulnerability">
      <metadata>
        <title>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1921" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1921"/>
        <description>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:22.739-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:35.330-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:18.407-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11294 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:43.539-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:58.707-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31903"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31997"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32058"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32011"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31769"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:31610"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-24.ent" test_ref="oval:org.mitre.oval:tst:32022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31993"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31996"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32047"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31303"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31718"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31829"/>
            <criterion comment="php is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31181"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32064"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31623"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31882"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31988"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:32010"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31662"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.7" test_ref="oval:org.mitre.oval:tst:31873"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11293" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0022"/>
        <description>Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:01.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:35.097-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:18.175-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11293 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:17.852-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:58.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" test_ref="oval:org.mitre.oval:tst:31133"/>
          <criterion comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" test_ref="oval:org.mitre.oval:tst:30769"/>
          <criterion comment="exim is earlier than 0:4.43-1.RHEL4.3" test_ref="oval:org.mitre.oval:tst:31290"/>
          <criterion comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" test_ref="oval:org.mitre.oval:tst:30863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11292" version="5" class="vulnerability">
      <metadata>
        <title>The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0965"/>
        <description>The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:39.121-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:34.845-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:17.899-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11292 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:32.075-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:57.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el3" test_ref="oval:org.mitre.oval:tst:31686"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gaim is earlier than 1:1.2.1-4.el4" test_ref="oval:org.mitre.oval:tst:31403"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11291" version="5" class="vulnerability">
      <metadata>
        <title>The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1160"/>
        <description>The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:29.286-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:34.365-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:17.397-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11291 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:57.923-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:57.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="thunderbird is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32113"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11290" version="5" class="vulnerability">
      <metadata>
        <title>unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4338" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4338"/>
        <description>unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:27.350-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:34.149-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:17.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11290 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:49.346-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:56.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-13.rhel3" test_ref="oval:org.mitre.oval:tst:32961"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-16.rhel4" test_ref="oval:org.mitre.oval:tst:32979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11289" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3606" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606"/>
        <description>Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:32.592-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:33.788-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:16.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11289 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:11.439-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:56.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="xpdf is earlier than 1:2.02-17.el3" test_ref="oval:org.mitre.oval:tst:39361"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11286" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3651" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3651"/>
        <description>Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:29.222-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:32.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:15.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11286 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:20.383-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:55.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32303"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32466"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32538"/>
            <criterion comment="ethereal is earlier than 0:0.10.14-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11283" version="5" class="vulnerability">
      <metadata>
        <title>The mprotect code (mprotect.c) in Linux 2.6 on Itanium IA64 Montecito processors does not properly maintain cache coherency as required by the architecture, which allows local users to cause a denial of service and possibly corrupt data by modifying PTE protections.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3105"/>
        <description>The mprotect code (mprotect.c) in Linux 2.6 on Itanium IA64 Montecito processors does not properly maintain cache coherency as required by the architecture, which allows local users to cause a denial of service and possibly corrupt data by modifying PTE protections.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:19.795-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:32.297-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:15.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11283 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:42.232-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:54.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11280" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c.  NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5031"/>
        <description>Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c.  NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:44.735-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:31.367-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:13.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11280 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:33.759-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:53.143-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38704"/>
            <criterion comment="tkinter is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38695"/>
            <criterion comment="python-tools is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38872"/>
            <criterion comment="python is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:38617"/>
            <criterion comment="python-docs is earlier than 0:2.2.3-6.11" test_ref="oval:org.mitre.oval:tst:37965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38916"/>
            <criterion comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38703"/>
            <criterion comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38787"/>
            <criterion comment="python is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38939"/>
            <criterion comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" test_ref="oval:org.mitre.oval:tst:38081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38889"/>
            <criterion comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38958"/>
            <criterion comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38827"/>
            <criterion comment="python is earlier than 0:2.4.3-24.el5_3.6" test_ref="oval:org.mitre.oval:tst:38282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11278" version="5" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142"/>
        <description>Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:00.669-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:30.862-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:13.478-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11278 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:45.498-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:52.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31265"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31218"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31097"/>
            <criterion comment="ethereal is earlier than 0:0.10.9-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11277" version="5" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2443"/>
        <description>Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:44.451-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:30.468-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:12.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11277 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:08.120-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:51.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33627"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34238"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34171"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33767"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34147"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34640"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34202"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34749"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34767"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34660"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34728"/>
            <criterion comment="krb5 is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34350"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34575"/>
            <criterion comment="krb5-server is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34729"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34195"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11276" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2949"/>
        <description>Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:10.364-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:29.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:12.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11276 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:37.652-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:51.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gimp-devel is earlier than 0:1.2.3-20.9.el3" test_ref="oval:org.mitre.oval:tst:34383"/>
            <criterion comment="gimp-perl is earlier than 0:1.2.3-20.9.el3" test_ref="oval:org.mitre.oval:tst:34552"/>
            <criterion comment="gimp is earlier than 0:1.2.3-20.9.el3" test_ref="oval:org.mitre.oval:tst:34504"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gimp-devel is earlier than 0:2.0.5-7.0.7.el4" test_ref="oval:org.mitre.oval:tst:34679"/>
            <criterion comment="gimp is earlier than 0:2.0.5-7.0.7.el4" test_ref="oval:org.mitre.oval:tst:34499"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gimp-libs is earlier than 0:2.2.13-2.0.7.el5" test_ref="oval:org.mitre.oval:tst:34469"/>
            <criterion comment="gimp-devel is earlier than 0:2.2.13-2.0.7.el5" test_ref="oval:org.mitre.oval:tst:34574"/>
            <criterion comment="gimp is earlier than 0:2.2.13-2.0.7.el5" test_ref="oval:org.mitre.oval:tst:34697"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11273" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3932"/>
        <description>Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:10.486-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:29.463-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:12.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11273 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:27.330-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:50.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11272" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212"/>
        <description>Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:33.098-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:29.008-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:11.614-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11272 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:54.431-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:50.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-71" test_ref="oval:org.mitre.oval:tst:39799"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-71" test_ref="oval:org.mitre.oval:tst:39761"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-71" test_ref="oval:org.mitre.oval:tst:39227"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-71" test_ref="oval:org.mitre.oval:tst:39626"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-71" test_ref="oval:org.mitre.oval:tst:39771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-62.el4_8.1" test_ref="oval:org.mitre.oval:tst:39242"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-62.el4_8.1" test_ref="oval:org.mitre.oval:tst:39546"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-62.el4_8.1" test_ref="oval:org.mitre.oval:tst:39236"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-62.el4_8.1" test_ref="oval:org.mitre.oval:tst:39715"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-62.el4_8.1" test_ref="oval:org.mitre.oval:tst:39679"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:39207"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:39532"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:39769"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:39828"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-36.el5_4.1" test_ref="oval:org.mitre.oval:tst:39572"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11271" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3) DHCP, (4) MEGACO dissector, or (5) H1 dissector in Ethereal 0.8.15 through 0.10.11 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2363"/>
        <description>Unknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3) DHCP, (4) MEGACO dissector, or (5) H1 dissector in Ethereal 0.8.15 through 0.10.11 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:31.295-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:28.760-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:11.351-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11271 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:12.192-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:49.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31966"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32076"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32122"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32035"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11267" version="5" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0773"/>
        <description>The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:32.411-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:27.938-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:10.410-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11267 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:34:33.792-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:48.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34475"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34659"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34630"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34375"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34496"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34560"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34493"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34302"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34295"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34662"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:33694"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11266" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351"/>
        <description>Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:18.598-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:26.931-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:09.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11266 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:51:52.679-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:47.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33447"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33884"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33550"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33984"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33936"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33976"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33799"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33867"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-6.el3" test_ref="oval:org.mitre.oval:tst:33835"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33958"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33791"/>
            <criterion comment="freetype is earlier than 0:2.1.4-6.el3" test_ref="oval:org.mitre.oval:tst:33906"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33929"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33764"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33070"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33716"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33788"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33928"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33930"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33951"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33950"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33932"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33656"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33963"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33466"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33846"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33660"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33687"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33689"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33499"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33719"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-120.EL" test_ref="oval:org.mitre.oval:tst:33696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33811"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33258"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-5.el4" test_ref="oval:org.mitre.oval:tst:33866"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33567"/>
            <criterion comment="freetype is earlier than 0:2.1.9-5.el4" test_ref="oval:org.mitre.oval:tst:33796"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33738"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-5.el4" test_ref="oval:org.mitre.oval:tst:33869"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33938"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33663"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33066"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33875"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33789"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33829"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33790"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33434"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33704"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-5.el4" test_ref="oval:org.mitre.oval:tst:33977"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33886"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33982"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33715"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33856"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" test_ref="oval:org.mitre.oval:tst:33815"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-17.el5" test_ref="oval:org.mitre.oval:tst:33677"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.2.el5" test_ref="oval:org.mitre.oval:tst:33903"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-17.el5" test_ref="oval:org.mitre.oval:tst:33827"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.2.el5" test_ref="oval:org.mitre.oval:tst:33674"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-17.el5" test_ref="oval:org.mitre.oval:tst:34015"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11265" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an encoded JPEG stream that is longer than the scan line size (TiffScanLineSize).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3460"/>
        <description>Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an encoded JPEG stream that is longer than the scan line size (TiffScanLineSize).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:50.665-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:26.647-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:09.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11265 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:20.422-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:46.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11264" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0446"/>
        <description>Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:30.465-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:26.424-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:08.806-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11264 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:39.214-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:46.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" test_ref="oval:org.mitre.oval:tst:31374"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" test_ref="oval:org.mitre.oval:tst:31315"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11263" version="5" class="vulnerability">
      <metadata>
        <title>Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invalid behavior in applications) on big-endian systems.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2448"/>
        <description>Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invalid behavior in applications) on big-endian systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:25.680-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:26.207-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:08.575-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11263 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:44.294-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:46.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32125"/>
          <criterion comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:32141"/>
          <criterion comment="kdenetwork is earlier than 7:3.3.1-2.3" test_ref="oval:org.mitre.oval:tst:31965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11261" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2292"/>
        <description>Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:51.710-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:25.771-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:07.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11261 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:06.750-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:45.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.24" test_ref="oval:org.mitre.oval:tst:36837"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.24" test_ref="oval:org.mitre.oval:tst:37027"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.24" test_ref="oval:org.mitre.oval:tst:37070"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.24" test_ref="oval:org.mitre.oval:tst:36912"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.24" test_ref="oval:org.mitre.oval:tst:36958"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.el4_6.11.3" test_ref="oval:org.mitre.oval:tst:36843"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.el4_6.11.3" test_ref="oval:org.mitre.oval:tst:36880"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.el4_6.11.3" test_ref="oval:org.mitre.oval:tst:36663"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.el4_6.11.3" test_ref="oval:org.mitre.oval:tst:37050"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.el4_6.11.3" test_ref="oval:org.mitre.oval:tst:36948"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.1" test_ref="oval:org.mitre.oval:tst:36969"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-24.el5_2.1" test_ref="oval:org.mitre.oval:tst:37054"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.1" test_ref="oval:org.mitre.oval:tst:36883"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.1" test_ref="oval:org.mitre.oval:tst:36847"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.1" test_ref="oval:org.mitre.oval:tst:36887"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11259" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3404"/>
        <description>Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:13.509-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:25.356-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:07.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11259 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:35:10.333-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:44.806-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="gimp-devel is earlier than 1:2.0.5-6" test_ref="oval:org.mitre.oval:tst:32652"/>
          <criterion comment="gimp is earlier than 1:2.0.5-6" test_ref="oval:org.mitre.oval:tst:32460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11258" version="5" class="vulnerability">
      <metadata>
        <title>The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846"/>
        <description>The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:51.133-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:24.860-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:06.805-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11258 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:43.008-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:44.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.23" test_ref="oval:org.mitre.oval:tst:35500"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.23" test_ref="oval:org.mitre.oval:tst:35214"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.23" test_ref="oval:org.mitre.oval:tst:35679"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.23" test_ref="oval:org.mitre.oval:tst:35260"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.23" test_ref="oval:org.mitre.oval:tst:35401"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.el4_6.11.1" test_ref="oval:org.mitre.oval:tst:35099"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.el4_6.11.1" test_ref="oval:org.mitre.oval:tst:35223"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.el4_6.11.1" test_ref="oval:org.mitre.oval:tst:35674"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.el4_6.11.1" test_ref="oval:org.mitre.oval:tst:35414"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.el4_6.11.1" test_ref="oval:org.mitre.oval:tst:35387"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-19.el5_1.1" test_ref="oval:org.mitre.oval:tst:35497"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-19.el5_1.1" test_ref="oval:org.mitre.oval:tst:35534"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-19.el5_1.1" test_ref="oval:org.mitre.oval:tst:35376"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-19.el5_1.1" test_ref="oval:org.mitre.oval:tst:35426"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-19.el5_1.1" test_ref="oval:org.mitre.oval:tst:35655"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11257" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1864"/>
        <description>Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:57.130-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:24.259-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:06.132-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11257 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:22.229-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:43.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34251"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33540"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33681"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34104"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34225"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33981"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33655"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34240"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33911"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34150"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:33287"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34209"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34018"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.5" test_ref="oval:org.mitre.oval:tst:34253"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34211"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34207"/>
            <criterion comment="php-common is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34065"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34113"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34217"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34013"/>
            <criterion comment="php is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34180"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:33453"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34056"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:33924"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34226"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:33397"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34129"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34250"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:33993"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34061"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34151"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34139"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-12.el5" test_ref="oval:org.mitre.oval:tst:34097"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11256" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1194"/>
        <description>Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:09.718-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:23.926-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:05.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11256 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:46.797-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:42.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="nasm is earlier than 0:0.98.35-3.EL3" test_ref="oval:org.mitre.oval:tst:31348"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nasm-doc is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31776"/>
            <criterion comment="nasm is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31746"/>
            <criterion comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" test_ref="oval:org.mitre.oval:tst:31654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11254" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2360"/>
        <description>Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:01.006-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:23.361-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:05.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11254 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:21.958-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:41.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31966"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32076"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32122"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32035"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11253" version="5" class="vulnerability">
      <metadata>
        <title>Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1173"/>
        <description>Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:25.469-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:23.053-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:04.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11253 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:03.000-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:41.573-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.12.11-4.RHEL3.6" test_ref="oval:org.mitre.oval:tst:32636"/>
            <criterion comment="sendmail-doc is earlier than 0:8.12.11-4.RHEL3.6" test_ref="oval:org.mitre.oval:tst:32247"/>
            <criterion comment="sendmail-cf is earlier than 0:8.12.11-4.RHEL3.6" test_ref="oval:org.mitre.oval:tst:32182"/>
            <criterion comment="sendmail-devel is earlier than 0:8.12.11-4.RHEL3.6" test_ref="oval:org.mitre.oval:tst:32742"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.13.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32406"/>
            <criterion comment="sendmail-doc is earlier than 0:8.13.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32603"/>
            <criterion comment="sendmail-cf is earlier than 0:8.13.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32526"/>
            <criterion comment="sendmail-devel is earlier than 0:8.13.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:32452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11252" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument.  NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4667"/>
        <description>Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument.  NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:40.461-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:22.795-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:04.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11252 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:03.822-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:41.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.50-35.EL3" test_ref="oval:org.mitre.oval:tst:30464"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="unzip is earlier than 0:5.51-9.EL4.5" test_ref="oval:org.mitre.oval:tst:33619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11250" version="5" class="vulnerability">
      <metadata>
        <title>The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3741"/>
        <description>The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:28.911-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:22.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:03.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11250 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:31:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:36:07.171-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:40.463-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11249" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0091"/>
        <description>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:47.506-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:22.008-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:03.547-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11249 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:45.547-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:40.088-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11245" version="5" class="vulnerability">
      <metadata>
        <title>A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6235"/>
        <description>A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:35.845-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:21.101-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:02.482-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11245 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:18:59.205-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:38.470-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.1-19" test_ref="oval:org.mitre.oval:tst:32348"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.6-8" test_ref="oval:org.mitre.oval:tst:33174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11243" version="5" class="vulnerability">
      <metadata>
        <title>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2272" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2272"/>
        <description>Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:36.109-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:20.789-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:02.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11243 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:48.485-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:38.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11239" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the BER dissector in Ethereal 0.10.11 allows remote attackers to cause a denial of service (abort or infinite loop) via unknown attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2366"/>
        <description>Unknown vulnerability in the BER dissector in Ethereal 0.10.11 allows remote attackers to cause a denial of service (abort or infinite loop) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:59.230-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:19.737-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:01.115-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11239 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:11.211-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:36.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31966"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32076"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32122"/>
            <criterion comment="ethereal is earlier than 0:0.10.12-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32035"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11237" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1097"/>
        <description>Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:57.378-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:18.987-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:09:00.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11237 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:04.256-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:35.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11236" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the request_key_auth_destroy function in request_key_auth in Linux kernel 2.6.10 up to 2.6.13 allows local users to cause a denial of service (memory consumption) via a large number of authorization token keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3119"/>
        <description>Memory leak in the request_key_auth_destroy function in request_key_auth in Linux kernel 2.6.10 up to 2.6.13 allows local users to cause a denial of service (memory consumption) via a large number of authorization token keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:04.334-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:18.727-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:59.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11236 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:29.880-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:35.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32382"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32096"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32404"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32387"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32210"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32355"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" test_ref="oval:org.mitre.oval:tst:32373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11235" version="5" class="vulnerability">
      <metadata>
        <title>choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1855" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1855"/>
        <description>choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:28.681-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:18.448-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:59.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11235 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:20.575-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:34.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11234" version="5" class="vulnerability">
      <metadata>
        <title>The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5754"/>
        <description>The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:48.900-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:17.836-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:59.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11234 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:46.846-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:34.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11233" version="5" class="vulnerability">
      <metadata>
        <title>The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3104"/>
        <description>The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:56.004-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:17.343-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:58.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11233 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:55.650-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:33.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34475"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34659"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34630"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34375"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34496"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34560"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34493"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34302"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34295"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:34662"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.2.EL" test_ref="oval:org.mitre.oval:tst:33694"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11232" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3806"/>
        <description>Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:06.178-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:16.791-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:58.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11232 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:12.223-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:33.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11231" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252"/>
        <description>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:23.729-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:16.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:57.895-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11231 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:10.519-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:32.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" test_ref="oval:org.mitre.oval:tst:38589"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" test_ref="oval:org.mitre.oval:tst:38719"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11230" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:29.378-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:15.988-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:57.370-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11230 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:29.576-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:32.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11229" version="5" class="vulnerability">
      <metadata>
        <title>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233"/>
        <description>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:18.804-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:15.650-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:56.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11229 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:16.126-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:31.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11228" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6169"/>
        <description>Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:08.707-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:15.430-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:56.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11228 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:10.450-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:31.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.1-19" test_ref="oval:org.mitre.oval:tst:32348"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gnupg is earlier than 0:1.2.6-8" test_ref="oval:org.mitre.oval:tst:33174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11227" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1571"/>
        <description>Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:30.801-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:14.864-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:56.143-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11227 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:54.103-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:30.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39910"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40282"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40001"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40160"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39327"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39963"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39749"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40277"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:39865"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.50.el3" test_ref="oval:org.mitre.oval:tst:40145"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40087"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40185"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40258"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40130"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40147"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-52.el4_8" test_ref="oval:org.mitre.oval:tst:40264"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11226" version="5" class="vulnerability">
      <metadata>
        <title>The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1693"/>
        <description>The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:08.656-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:14.575-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:55.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11226 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:01.218-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:29.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 0:3.3.1-9.el4_6" test_ref="oval:org.mitre.oval:tst:36440"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2" test_ref="oval:org.mitre.oval:tst:36630"/>
            <criterion comment="xpdf is earlier than 1:3.00-16.el4" test_ref="oval:org.mitre.oval:tst:36487"/>
            <criterion comment="kdegraphics is earlier than 0:3.3.1-9.el4_6" test_ref="oval:org.mitre.oval:tst:36266"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_1" test_ref="oval:org.mitre.oval:tst:36674"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_1" test_ref="oval:org.mitre.oval:tst:36617"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_1" test_ref="oval:org.mitre.oval:tst:36491"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11225" version="5" class="vulnerability">
      <metadata>
        <title>ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563"/>
        <description>ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:35:02.078-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:14.316-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:55.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11225 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:39.605-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:29.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.1.2-6.el3" test_ref="oval:org.mitre.oval:tst:39300"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_8.1" test_ref="oval:org.mitre.oval:tst:39285"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="ntp is earlier than 0:4.2.2p1-9.el5_4.1" test_ref="oval:org.mitre.oval:tst:38798"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11224" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename.  NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2480"/>
        <description>Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename.  NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:30.146-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:14.129-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:55.293-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11224 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:30.727-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:29.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="dia is earlier than 1:0.94-5.7.1" test_ref="oval:org.mitre.oval:tst:32057"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11223" version="5" class="vulnerability">
      <metadata>
        <title>The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3085"/>
        <description>The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:17.350-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:13.669-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:54.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11223 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:44.226-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:28.480-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39474"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39423"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39307"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39264"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39332"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39395"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39376"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39381"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39246"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39428"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39414"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39006"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:38683"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39404"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39139"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39341"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11222" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777"/>
        <description>Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:00.670-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:13.410-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:54.512-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11222 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:17.471-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:28.068-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11219" version="5" class="vulnerability">
      <metadata>
        <title>layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382"/>
        <description>layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:24.337-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:12.865-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:53.762-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11219 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:13.577-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:27.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11218" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376"/>
        <description>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:55.320-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:12.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:53.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11218 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:57.500-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:26.506-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39570"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39466"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39720"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39691"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39583"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39727"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39575"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" test_ref="oval:org.mitre.oval:tst:39724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:39525"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39481"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" test_ref="oval:org.mitre.oval:tst:38755"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39675"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el4" test_ref="oval:org.mitre.oval:tst:39710"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39683"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39031"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39547"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" test_ref="oval:org.mitre.oval:tst:39753"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39602"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39541"/>
            <criterion comment="nspr is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39168"/>
            <criterion comment="firefox is earlier than 0:3.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39294"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" test_ref="oval:org.mitre.oval:tst:39579"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" test_ref="oval:org.mitre.oval:tst:39636"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11217" version="5" class="vulnerability">
      <metadata>
        <title>The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1196"/>
        <description>The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:57.218-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:11.979-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:52.818-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11217 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:02.965-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:26.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38765"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:37797"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.62" test_ref="oval:org.mitre.oval:tst:38735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38351"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38503"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" test_ref="oval:org.mitre.oval:tst:38748"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11215" version="5" class="vulnerability">
      <metadata>
        <title>The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which triggers a NULL pointer dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6694"/>
        <description>The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:28.228-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:11.282-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:51.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11215 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:27.743-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:25.071-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36192"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36176"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36335"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36430"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35944"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36215"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36409"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35484"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35974"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35791"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36150"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11213" version="5" class="vulnerability">
      <metadata>
        <title>Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5925" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5925"/>
        <description>Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:37.739-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:10.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:51.471-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11213 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:31.927-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:24.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="elinks is earlier than 0:0.9.2-3.3" test_ref="oval:org.mitre.oval:tst:33186"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11212" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4337"/>
        <description>Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:09.238-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:10.556-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:51.232-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11212 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:35.753-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:23.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-13.rhel3" test_ref="oval:org.mitre.oval:tst:32961"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-16.rhel4" test_ref="oval:org.mitre.oval:tst:32979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11211" version="5" class="vulnerability">
      <metadata>
        <title>The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5899"/>
        <description>The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:54.204-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:09.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:50.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11211 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:22.457-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:22.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:37185"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:36983"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:36761"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:37254"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:37280"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:36584"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-48.ent" test_ref="oval:org.mitre.oval:tst:37255"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37302"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37269"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:36771"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:36854"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37155"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37143"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:36781"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37125"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37202"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37223"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37010"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37319"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37113"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.12" test_ref="oval:org.mitre.oval:tst:37239"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:36927"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37138"/>
            <criterion comment="php-common is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37146"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37179"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37204"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:36955"/>
            <criterion comment="php is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37260"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37282"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:36878"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37114"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:36634"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37118"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37283"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37127"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37086"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37328"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37036"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37144"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-20.el5_2.1" test_ref="oval:org.mitre.oval:tst:37165"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11210" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563"/>
        <description>Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:48.928-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:09.320-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:50.133-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11210 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:28.543-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:22.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11208" version="5" class="vulnerability">
      <metadata>
        <title>The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2869"/>
        <description>The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:24.696-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:08.102-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:48.742-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11208 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:42.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:21.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34409"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34257"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34432"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33988"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33721"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33693"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34313"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34281"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:33894"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" test_ref="oval:org.mitre.oval:tst:34228"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:33625"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33931"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33844"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34331"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34334"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34021"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34249"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.el4" test_ref="oval:org.mitre.oval:tst:34293"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.1.el4" test_ref="oval:org.mitre.oval:tst:34371"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34446"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34262"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34366"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:33994"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" test_ref="oval:org.mitre.oval:tst:34322"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34445"/>
            <criterion comment="yelp is earlier than 0:2.16.0-15.el5" test_ref="oval:org.mitre.oval:tst:33445"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34323"/>
            <criterion comment="devhelp is earlier than 0:0.12-11.el5" test_ref="oval:org.mitre.oval:tst:34204"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:34162"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-1.el5" test_ref="oval:org.mitre.oval:tst:33979"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11207" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792"/>
        <description>Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:23.169-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:07.710-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:48.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11207 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:51.177-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:20.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="hpijs is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38025"/>
            <criterion comment="ghostscript-devel is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38598"/>
            <criterion comment="ghostscript is earlier than 0:7.05-32.1.20" test_ref="oval:org.mitre.oval:tst:38506"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38482"/>
            <criterion comment="ghostscript is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38656"/>
            <criterion comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.8" test_ref="oval:org.mitre.oval:tst:38408"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38588"/>
            <criterion comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38629"/>
            <criterion comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" test_ref="oval:org.mitre.oval:tst:38457"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11206" version="5" class="vulnerability">
      <metadata>
        <title>The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337"/>
        <description>The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:09.211-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:07.092-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:47.687-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11206 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:26.849-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:20.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39591"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39396"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39586"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39171"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39299"/>
            <criterion comment="kernel is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39151"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39468"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:39460"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-63.EL" test_ref="oval:org.mitre.oval:tst:38810"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38666"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38450"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38769"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:37790"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38592"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38678"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38363"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38714"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38581"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38538"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.EL" test_ref="oval:org.mitre.oval:tst:38439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38663"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38680"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38674"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38654"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38700"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38368"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38726"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38390"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38547"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38412"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38701"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" test_ref="oval:org.mitre.oval:tst:38129"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11205" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0755"/>
        <description>Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:35.503-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:06.850-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:47.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11205 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:52.095-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:19.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" test_ref="oval:org.mitre.oval:tst:31609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11204" version="5" class="vulnerability">
      <metadata>
        <title>lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929.  NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4690"/>
        <description>lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929.  NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:37.886-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:06.598-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:47.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11204 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:34:40.411-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:19.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-11.3" test_ref="oval:org.mitre.oval:tst:37424"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" test_ref="oval:org.mitre.oval:tst:37925"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" test_ref="oval:org.mitre.oval:tst:37898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11203" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3432"/>
        <description>Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:50.812-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:06.286-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:46.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11203 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:48.487-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:18.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37217"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37049"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37429"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37390"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37492"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37521"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37326"/>
            <criterion comment="vim is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:36926"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37520"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37284"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11202" version="5" class="vulnerability">
      <metadata>
        <title>A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790"/>
        <description>A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:14.826-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:05.747-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:46.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11202 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:27:00.394-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:33:31.990-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:18.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11199" version="5" class="vulnerability">
      <metadata>
        <title>The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3546"/>
        <description>The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:17.629-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:04.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:44.931-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11199 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:32.242-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:16.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39717"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39629"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39915"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39741"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:40003"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39901"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39326"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39619"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39111"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39417"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39642"/>
            <criterion comment="php is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39899"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39821"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_8.1" test_ref="oval:org.mitre.oval:tst:39615"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39627"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39886"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39848"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39908"/>
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39580"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_8.1" test_ref="oval:org.mitre.oval:tst:39670"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39927"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:40010"/>
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_8.1" test_ref="oval:org.mitre.oval:tst:39559"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39461"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39883"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39544"/>
            <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39804"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39875"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39748"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39802"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39854"/>
            <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39053"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39980"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39581"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39954"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39488"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39018"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39463"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39634"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39436"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39969"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39698"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39664"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39913"/>
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39431"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11198" version="5" class="vulnerability">
      <metadata>
        <title>initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3629"/>
        <description>initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:54.685-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:04.398-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:44.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11198 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:24.987-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:16.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="initscripts is earlier than 0:7.31.30.EL-1" test_ref="oval:org.mitre.oval:tst:32225"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="initscripts is earlier than 0:7.93.24.EL-1.1" test_ref="oval:org.mitre.oval:tst:32220"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11194" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4681"/>
        <description>Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:54.111-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:03.284-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:43.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11194 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:05.700-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:14.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11193" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:26.641-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:02.290-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:42.273-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11193 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:14.818-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:13.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38173"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38181"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38221"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38323"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38241"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38337"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:37355"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38135"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38326"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" test_ref="oval:org.mitre.oval:tst:38186"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38184"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38228"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37943"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:37433"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38309"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" test_ref="oval:org.mitre.oval:tst:38278"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11192" version="5" class="vulnerability">
      <metadata>
        <title>dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0095"/>
        <description>dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:26.327-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:01.962-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:41.935-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11192 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:04.359-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:13.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32212"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:31918"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32469"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32434"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32401"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32060"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32347"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32240"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.EL" test_ref="oval:org.mitre.oval:tst:32399"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11191" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0584"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:14.514-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:01.638-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:41.587-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11191 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:53:30.868-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:12.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11188" version="5" class="vulnerability">
      <metadata>
        <title>Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1808"/>
        <description>Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:37.690-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:01.084-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:40.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11188 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:15.113-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:11.463-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:37450"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38284"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38008"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.4-12.el3" test_ref="oval:org.mitre.oval:tst:38245"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38414"/>
            <criterion comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38395"/>
            <criterion comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38442"/>
            <criterion comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" test_ref="oval:org.mitre.oval:tst:38234"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freetype is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37321"/>
            <criterion comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37312"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" test_ref="oval:org.mitre.oval:tst:37160"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11187" version="5" class="vulnerability">
      <metadata>
        <title>The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0028"/>
        <description>The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:19.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:08:00.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:40.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11187 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:29.532-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:10.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38437"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38348"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:37805"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38116"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38721"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38384"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38346"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38490"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38262"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38289"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" test_ref="oval:org.mitre.oval:tst:38302"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38113"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38107"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38167"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38064"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38380"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37672"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38093"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38127"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38109"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38430"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:37764"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" test_ref="oval:org.mitre.oval:tst:38397"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11186" version="5" class="vulnerability">
      <metadata>
        <title>The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5022"/>
        <description>The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:51.102-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:59.903-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:39.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11186 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:42:41.838-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:09.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11185" version="5" class="vulnerability">
      <metadata>
        <title>The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0908"/>
        <description>The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:00.858-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:58.990-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:38.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11185 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:03.783-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:08.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11182" version="5" class="vulnerability">
      <metadata>
        <title>The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3272" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3272"/>
        <description>The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:02.357-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:58.058-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:37.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11182 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:53.239-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:07.407-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37470"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37734"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37826"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37656"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37782"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37432"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37747"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37811"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37951"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37485"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" test_ref="oval:org.mitre.oval:tst:37662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37589"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37288"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37600"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37692"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37104"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37681"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37688"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37710"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37698"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37703"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37665"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.13.el5" test_ref="oval:org.mitre.oval:tst:37649"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11176" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0941"/>
        <description>Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:08.149-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:56.440-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:36.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11176 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:43:00.327-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:52:59.168-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:04.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31045"/>
            <criterion comment="gd-devel is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31109"/>
            <criterion comment="gd-progs is earlier than 0:1.8.4-12.3.1" test_ref="oval:org.mitre.oval:tst:31083"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.28-4.4E.1" test_ref="oval:org.mitre.oval:tst:32218"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-4.4E.1" test_ref="oval:org.mitre.oval:tst:32334"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-4.4E.1" test_ref="oval:org.mitre.oval:tst:32294"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11174" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404"/>
        <description>Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:05.764-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:55.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:35.304-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11174 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:35:00.132-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:43:36.941-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:03.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38261"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38777"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38528"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38998"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38804"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38780"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38691"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38019"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38293"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.41.el3" test_ref="oval:org.mitre.oval:tst:38982"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.3.99.3-1.el4_8.2" test_ref="oval:org.mitre.oval:tst:38342"/>
            <criterion comment="nspr is earlier than 0:4.7.4-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38829"/>
            <criterion comment="nss is earlier than 0:3.12.3.99.3-1.el4_8.2" test_ref="oval:org.mitre.oval:tst:38630"/>
            <criterion comment="nss-tools is earlier than 0:3.12.3.99.3-1.el4_8.2" test_ref="oval:org.mitre.oval:tst:38960"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.4-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:38731"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38999"/>
            <criterion comment="nss-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38609"/>
            <criterion comment="nspr is earlier than 0:4.7.4-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38995"/>
            <criterion comment="nss is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38950"/>
            <criterion comment="nss-tools is earlier than 0:3.12.3.99.3-1.el5_3.2" test_ref="oval:org.mitre.oval:tst:38841"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.4-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11169" version="5" class="vulnerability">
      <metadata>
        <title>Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0626"/>
        <description>Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:43.701-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:54.783-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:34.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11169 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:31.620-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:02.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" test_ref="oval:org.mitre.oval:tst:31246"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" test_ref="oval:org.mitre.oval:tst:31854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11168" version="5" class="vulnerability">
      <metadata>
        <title>The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3238"/>
        <description>The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:38.968-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:54.311-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:33.589-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11168 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:13.522-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:01.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39101"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39357"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38568"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39331"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39316"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39054"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39274"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39407"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39435"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:39442"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" test_ref="oval:org.mitre.oval:tst:38473"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11166" version="5" class="vulnerability">
      <metadata>
        <title>The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0160"/>
        <description>The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:07.597-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:53.666-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:32.916-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11166 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:09.558-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:12:00.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11164" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:21.571-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:52.918-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:32.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11164 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:44.213-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:59.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11163" version="5" class="vulnerability">
      <metadata>
        <title>GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1241"/>
        <description>GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:58.188-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:52.385-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:31.501-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11163 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:51.548-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:59.210-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11160" version="5" class="vulnerability">
      <metadata>
        <title>The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0008"/>
        <description>The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:01.576-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:51.259-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:30.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11160 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:04.191-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:58.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40241"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40097"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40139"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40308"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40210"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40082"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40354"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:40326"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39940"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39363"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.23.EL" test_ref="oval:org.mitre.oval:tst:39805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40228"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40098"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40231"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39918"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39938"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40088"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40237"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39997"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40240"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40352"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:39930"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.15.1.el5" test_ref="oval:org.mitre.oval:tst:40055"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11159" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow.  NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4137" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4137"/>
        <description>Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow.  NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:04.004-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:50.732-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:29.690-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11159 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:05.687-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:57.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:34921"/>
            <criterion comment="qt is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35117"/>
            <criterion comment="qt-devel is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35255"/>
            <criterion comment="qt-MySQL is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35041"/>
            <criterion comment="qt-ODBC is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:34922"/>
            <criterion comment="qt-designer is earlier than 1:3.1.2-17.RHEL3" test_ref="oval:org.mitre.oval:tst:35004"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35085"/>
            <criterion comment="qt is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35125"/>
            <criterion comment="qt-devel is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35050"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35175"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:34568"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:34886"/>
            <criterion comment="qt-designer is earlier than 1:3.3.3-13.RHEL4" test_ref="oval:org.mitre.oval:tst:35054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="qt-config is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34806"/>
            <criterion comment="qt is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34816"/>
            <criterion comment="qt-MySQL is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34466"/>
            <criterion comment="qt-ODBC is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35271"/>
            <criterion comment="qt-designer is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:34736"/>
            <criterion comment="qt-devel is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35097"/>
            <criterion comment="qt-PostgreSQL is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35149"/>
            <criterion comment="qt-devel-docs is earlier than 1:3.3.6-23.el5" test_ref="oval:org.mitre.oval:tst:35114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11158" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1092"/>
        <description>Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:53.627-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:50.231-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:29.164-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11158 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:06.964-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:56.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11156" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2028"/>
        <description>Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:22.220-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:49.853-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:28.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11156 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:45.344-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:56.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="freeradius is earlier than 0:1.0.1-2.RHEL3.4" test_ref="oval:org.mitre.oval:tst:33848"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:33896"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:33347"/>
            <criterion comment="freeradius is earlier than 0:1.0.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:34215"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4.5" test_ref="oval:org.mitre.oval:tst:33852"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="freeradius-mysql is earlier than 0:1.1.3-1.2.el5" test_ref="oval:org.mitre.oval:tst:34157"/>
            <criterion comment="freeradius-unixODBC is earlier than 0:1.1.3-1.2.el5" test_ref="oval:org.mitre.oval:tst:33406"/>
            <criterion comment="freeradius is earlier than 0:1.1.3-1.2.el5" test_ref="oval:org.mitre.oval:tst:34112"/>
            <criterion comment="freeradius-postgresql is earlier than 0:1.1.3-1.2.el5" test_ref="oval:org.mitre.oval:tst:33854"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11155" version="5" class="vulnerability">
      <metadata>
        <title>The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4005"/>
        <description>The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:10.157-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:49.544-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:28.399-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11155 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:00.529-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:55.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39984"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40053"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39873"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39932"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39894"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39858"/>
          <criterion comment="kernel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40016"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39833"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39555"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39325"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40011"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11154" version="5" class="vulnerability">
      <metadata>
        <title>CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0417"/>
        <description>CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:28.349-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:48.789-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:27.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11154 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:03.513-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:55.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11152" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0586"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:05.608-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:48.160-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:27.101-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11152 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:59:00.488-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:03:17.472-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:54.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11151" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4063"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:08.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:47.752-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:26.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11151 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:28:46.430-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:53.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11149" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387"/>
        <description>Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:34.576-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:46.730-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:25.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11149 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:49.102-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:52.378-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34658"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34842"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34798"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.45" test_ref="oval:org.mitre.oval:tst:34753"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34413"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.45" test_ref="oval:org.mitre.oval:tst:34436"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34841"/>
            <criterion comment="xpdf is earlier than 1:2.02-10.RHEL3" test_ref="oval:org.mitre.oval:tst:34945"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.10" test_ref="oval:org.mitre.oval:tst:34721"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.45" test_ref="oval:org.mitre.oval:tst:34745"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34583"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-4.RHEL4" test_ref="oval:org.mitre.oval:tst:34861"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34394"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-4.RHEL4" test_ref="oval:org.mitre.oval:tst:34314"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34143"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2" test_ref="oval:org.mitre.oval:tst:34428"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34900"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7" test_ref="oval:org.mitre.oval:tst:34693"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2" test_ref="oval:org.mitre.oval:tst:34799"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34822"/>
            <criterion comment="xpdf is earlier than 1:3.00-12.RHEL4" test_ref="oval:org.mitre.oval:tst:34599"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34702"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.8" test_ref="oval:org.mitre.oval:tst:34643"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2" test_ref="oval:org.mitre.oval:tst:34757"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-2.el5" test_ref="oval:org.mitre.oval:tst:34637"/>
            <criterion comment="cups-lpd is earlier than 1:1.2.4-11.5.3.el5" test_ref="oval:org.mitre.oval:tst:34703"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34259"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-2.el5" test_ref="oval:org.mitre.oval:tst:34899"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.1.el5" test_ref="oval:org.mitre.oval:tst:34090"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34876"/>
            <criterion comment="cups-libs is earlier than 1:1.2.4-11.5.3.el5" test_ref="oval:org.mitre.oval:tst:34847"/>
            <criterion comment="tetex is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34952"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34695"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.1.el5" test_ref="oval:org.mitre.oval:tst:34785"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34961"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.1.el5" test_ref="oval:org.mitre.oval:tst:34926"/>
            <criterion comment="cups-devel is earlier than 1:1.2.4-11.5.3.el5" test_ref="oval:org.mitre.oval:tst:34800"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34882"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.1.el5" test_ref="oval:org.mitre.oval:tst:34652"/>
            <criterion comment="cups is earlier than 1:1.2.4-11.5.3.el5" test_ref="oval:org.mitre.oval:tst:34651"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11148" version="5" class="vulnerability">
      <metadata>
        <title>The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1267"/>
        <description>The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:00.136-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:46.509-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:25.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11148 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:29:20.320-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:51.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="arpwatch is earlier than 14:2.1a13-10.RHEL4" test_ref="oval:org.mitre.oval:tst:32040"/>
          <criterion comment="libpcap is earlier than 14:0.8.3-10.RHEL4" test_ref="oval:org.mitre.oval:tst:31954"/>
          <criterion comment="tcpdump is earlier than 14:3.8.2-10.RHEL4" test_ref="oval:org.mitre.oval:tst:31923"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11147" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3996"/>
        <description>Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:42.998-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:45.748-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:24.522-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11147 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:32.821-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:50.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11146" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094"/>
        <description>Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:05.957-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:45.521-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:24.265-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11146 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:47.092-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:50.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11144" version="5" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1137" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1137"/>
        <description>Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:43.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:44.886-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:23.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11144 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:00.368-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:49.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:31101"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30944"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30205"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30752"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30999"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30940"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:31177"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30903"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.1.EL" test_ref="oval:org.mitre.oval:tst:30786"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11139" version="5" class="vulnerability">
      <metadata>
        <title>The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5913"/>
        <description>The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:05.090-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:43.663-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:22.119-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11139 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:25:00.657-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:30:39.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:47.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="firefox is earlier than 0:3.6.4-8.el4" test_ref="oval:org.mitre.oval:tst:40755"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40435"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40552"/>
            <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40721"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40480"/>
            <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40813"/>
            <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40221"/>
            <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40385"/>
            <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:40828"/>
            <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40814"/>
            <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:40524"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40620"/>
            <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40722"/>
            <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:40273"/>
            <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11138" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774"/>
        <description>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:12.555-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:43.154-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:21.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11138 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:18.142-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:46.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38413"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38419"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38110"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38217"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37995"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37833"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38347"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38410"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:37953"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" test_ref="oval:org.mitre.oval:tst:38386"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:37842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-19.el4" test_ref="oval:org.mitre.oval:tst:38238"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38355"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el4" test_ref="oval:org.mitre.oval:tst:38405"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38148"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38132"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38204"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" test_ref="oval:org.mitre.oval:tst:38364"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38168"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:37685"/>
            <criterion comment="firefox is earlier than 0:3.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38372"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.21-1.el5" test_ref="oval:org.mitre.oval:tst:37944"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.7-1.el5" test_ref="oval:org.mitre.oval:tst:38365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11135" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1216"/>
        <description>Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:24.913-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:42.096-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:20.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11135 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:58:37.628-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:45.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-61" test_ref="oval:org.mitre.oval:tst:33590"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-61" test_ref="oval:org.mitre.oval:tst:33826"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-61" test_ref="oval:org.mitre.oval:tst:32858"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-61" test_ref="oval:org.mitre.oval:tst:33622"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-61" test_ref="oval:org.mitre.oval:tst:33700"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-46" test_ref="oval:org.mitre.oval:tst:33804"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-46" test_ref="oval:org.mitre.oval:tst:33812"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-46" test_ref="oval:org.mitre.oval:tst:33795"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-46" test_ref="oval:org.mitre.oval:tst:32895"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-46" test_ref="oval:org.mitre.oval:tst:33816"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="krb5-workstation is earlier than 0:1.5-23" test_ref="oval:org.mitre.oval:tst:33344"/>
            <criterion comment="krb5 is earlier than 0:1.5-23" test_ref="oval:org.mitre.oval:tst:33714"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-23" test_ref="oval:org.mitre.oval:tst:33831"/>
            <criterion comment="krb5-server is earlier than 0:1.5-23" test_ref="oval:org.mitre.oval:tst:33885"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-23" test_ref="oval:org.mitre.oval:tst:33785"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11134" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186"/>
        <description>Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:59.882-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:41.817-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:20.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11134 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:47.828-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:45.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-24.4" test_ref="oval:org.mitre.oval:tst:30796"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="enscript is earlier than 0:1.6.1-28.3" test_ref="oval:org.mitre.oval:tst:31274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11132" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572"/>
        <description>Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:24.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:41.104-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:19.527-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11132 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:57:39.684-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:44.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.14.1" test_ref="oval:org.mitre.oval:tst:35031"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.14.1" test_ref="oval:org.mitre.oval:tst:35544"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.14.1" test_ref="oval:org.mitre.oval:tst:35435"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.14.1" test_ref="oval:org.mitre.oval:tst:35042"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.25b-1.el4_6.2" test_ref="oval:org.mitre.oval:tst:35587"/>
            <criterion comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.2" test_ref="oval:org.mitre.oval:tst:35430"/>
            <criterion comment="samba-client is earlier than 0:3.0.25b-1.el4_6.2" test_ref="oval:org.mitre.oval:tst:35567"/>
            <criterion comment="samba is earlier than 0:3.0.25b-1.el4_6.2" test_ref="oval:org.mitre.oval:tst:35285"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="samba-common is earlier than 0:3.0.25b-1.el5_1.2" test_ref="oval:org.mitre.oval:tst:34598"/>
            <criterion comment="samba-swat is earlier than 0:3.0.25b-1.el5_1.2" test_ref="oval:org.mitre.oval:tst:35588"/>
            <criterion comment="samba-client is earlier than 0:3.0.25b-1.el5_1.2" test_ref="oval:org.mitre.oval:tst:35579"/>
            <criterion comment="samba is earlier than 0:3.0.25b-1.el5_1.2" test_ref="oval:org.mitre.oval:tst:35226"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11130" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2707" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2707"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:23.848-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:40.325-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:18.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11130 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T15:53:00.376-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:59:10.970-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:43.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32169"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:31729"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32242"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32151"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32014"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32144"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32068"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32248"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32293"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" test_ref="oval:org.mitre.oval:tst:32044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32244"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32012"/>
            <criterion comment="mozilla is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:31897"/>
            <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32300"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32226"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32289"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.7" test_ref="oval:org.mitre.oval:tst:32170"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32150"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32302"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32090"/>
            <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32209"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" test_ref="oval:org.mitre.oval:tst:32088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11129" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4144"/>
        <description>Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:16.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:39.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:18.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11129 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:03.261-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:42.877-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32037"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32699"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32588"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32852"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32735"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32383"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32971"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32748"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32946"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32537"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11127" version="5" class="vulnerability">
      <metadata>
        <title>The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6601" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6601"/>
        <description>The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:40.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:38.919-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:17.374-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11127 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:56.924-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:41.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:36102"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35807"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35304"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35743"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35830"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35938"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35951"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35406"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35943"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35867"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.21-1" test_ref="oval:org.mitre.oval:tst:35930"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35948"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35993"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36045"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35949"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36098"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36066"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35942"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36105"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35835"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:35597"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" test_ref="oval:org.mitre.oval:tst:36094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35261"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35907"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35319"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35123"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35894"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35781"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36109"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35308"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:35856"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" test_ref="oval:org.mitre.oval:tst:36044"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11125" version="5" class="vulnerability">
      <metadata>
        <title>SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3351"/>
        <description>SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:50.295-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:38.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:16.895-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11125 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:18:00.420-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:41.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="spamassassin is earlier than 0:3.0.5-3.el4" test_ref="oval:org.mitre.oval:tst:32493"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11124" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3102"/>
        <description>Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:34.432-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:38.143-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:16.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11124 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:57.454-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:40.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.24" test_ref="oval:org.mitre.oval:tst:34791"/>
            <criterion comment="pam-devel is earlier than 0:0.77-66.23" test_ref="oval:org.mitre.oval:tst:34850"/>
            <criterion comment="pam is earlier than 0:0.77-66.23" test_ref="oval:org.mitre.oval:tst:34954"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.24" test_ref="oval:org.mitre.oval:tst:34819"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.24" test_ref="oval:org.mitre.oval:tst:34393"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.24" test_ref="oval:org.mitre.oval:tst:34713"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.24" test_ref="oval:org.mitre.oval:tst:34877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openssh is earlier than 0:4.3p2-24.el5" test_ref="oval:org.mitre.oval:tst:34395"/>
            <criterion comment="pam-devel is earlier than 0:0.99.6.2-3.26.el5" test_ref="oval:org.mitre.oval:tst:34670"/>
            <criterion comment="pam is earlier than 0:0.99.6.2-3.26.el5" test_ref="oval:org.mitre.oval:tst:34359"/>
            <criterion comment="openssh-askpass is earlier than 0:4.3p2-24.el5" test_ref="oval:org.mitre.oval:tst:34563"/>
            <criterion comment="openssh-server is earlier than 0:4.3p2-24.el5" test_ref="oval:org.mitre.oval:tst:34696"/>
            <criterion comment="openssh-clients is earlier than 0:4.3p2-24.el5" test_ref="oval:org.mitre.oval:tst:34627"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11122" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089"/>
        <description>Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:56.533-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:37.322-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:15.602-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11122 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:07.298-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:39.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11121" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2802"/>
        <description>Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:45.704-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:36.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:14.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11121 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:08:46.873-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:38.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11119" version="5" class="vulnerability">
      <metadata>
        <title>ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0756"/>
        <description>ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:30.835-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:36.010-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:14.231-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11119 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:36.411-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:37.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11116" version="5" class="vulnerability">
      <metadata>
        <title>MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4030"/>
        <description>MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:13.003-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:35.426-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:13.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11116 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:46.576-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:36.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39929"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:39985"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40068"/>
            <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4_8.3" test_ref="oval:org.mitre.oval:tst:40047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:40085"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39585"/>
            <criterion comment="mysql-test is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:40252"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:40320"/>
            <criterion comment="mysql-server is earlier than 0:5.0.77-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11113" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1177"/>
        <description>Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:41.207-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:34.909-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:12.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11113 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:04:00.787-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:09:53.695-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:35.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5-25.rhel3" test_ref="oval:org.mitre.oval:tst:31464"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="mailman is earlier than 3:2.1.5-33.rhel4" test_ref="oval:org.mitre.oval:tst:31552"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11110" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4257"/>
        <description>Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:24.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:34.193-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:12.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11110 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:48.546-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:35.072-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11109" version="5" class="vulnerability">
      <metadata>
        <title>Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw.  NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298.  NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2712"/>
        <description>Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw.  NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298.  NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:31.199-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:33.704-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:11.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11109 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:50.552-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:34.446-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37217"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37049"/>
            <criterion comment="vim is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37429"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37390"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-0.30E.11" test_ref="oval:org.mitre.oval:tst:37492"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37521"/>
            <criterion comment="vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37326"/>
            <criterion comment="vim is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:36926"/>
            <criterion comment="vim-X11 is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37520"/>
            <criterion comment="vim-common is earlier than 1:6.3.046-1.el4_7.5z" test_ref="oval:org.mitre.oval:tst:37284"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37412"/>
            <criterion comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37218"/>
            <criterion comment="vim is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37405"/>
            <criterion comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37384"/>
            <criterion comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" test_ref="oval:org.mitre.oval:tst:37365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11108" version="5" class="vulnerability">
      <metadata>
        <title>gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1367"/>
        <description>gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:06.236-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:33.076-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:10.892-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11108 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:18:24.097-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:33.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35915"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:35794"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36513"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36264"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36161"/>
            <criterion comment="kernel is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36518"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36597"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36612"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-57.EL" test_ref="oval:org.mitre.oval:tst:36171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36972"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36412"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36840"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36741"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36936"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36433"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36961"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36949"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36894"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:36367"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.20.EL" test_ref="oval:org.mitre.oval:tst:37020"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36107"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36600"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36529"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36526"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36442"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36238"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36463"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36480"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35876"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36532"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36278"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:35724"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.19.el5" test_ref="oval:org.mitre.oval:tst:36560"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11107" version="5" class="vulnerability">
      <metadata>
        <title>The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206"/>
        <description>The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:04.796-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:32.717-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:10.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11107 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:28.803-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:33.152-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.27" test_ref="oval:org.mitre.oval:tst:30818"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.6" test_ref="oval:org.mitre.oval:tst:30695"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.27" test_ref="oval:org.mitre.oval:tst:31392"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.27" test_ref="oval:org.mitre.oval:tst:31250"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gpdf is earlier than 0:2.8.2-4.3" test_ref="oval:org.mitre.oval:tst:30790"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:30919"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.5" test_ref="oval:org.mitre.oval:tst:30331"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31056"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" test_ref="oval:org.mitre.oval:tst:31093"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11105" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2968" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2968"/>
        <description>Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:02.894-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:32.517-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:09.608-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11105 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:17:46.720-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:32.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="firefox is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:32147"/>
          <criterion comment="thunderbird is earlier than 0:1.0.7-1.4.1" test_ref="oval:org.mitre.oval:tst:31477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11104" version="5" class="vulnerability">
      <metadata>
        <title>crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink.  NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1038"/>
        <description>crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink.  NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:22.616-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:32.296-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:09.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11104 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:10:00.062-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:17:36.701-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:32.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="           The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="vixie-cron is earlier than 0:4.1-10.EL3" test_ref="oval:org.mitre.oval:tst:32494"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="vixie-cron is earlier than 4:4.1-36.EL4" test_ref="oval:org.mitre.oval:tst:31057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11100" version="5" class="vulnerability">
      <metadata>
        <title>The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1931" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1931"/>
        <description>The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:39.695-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:30.932-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:07.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11100 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:14:00.096-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:16:44.325-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:31.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="ruby-mode is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32572"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32552"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32367"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32099"/>
          <criterion comment="ruby is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32685"/>
          <criterion comment="irb is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32714"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.1-7.EL4.3" test_ref="oval:org.mitre.oval:tst:32276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11099" version="5" class="vulnerability">
      <metadata>
        <title>GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3490" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3490"/>
        <description>GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:35.586-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:30.680-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:07.633-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11099 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:30.522-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:30.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.2-0.30E.1" test_ref="oval:org.mitre.oval:tst:39672"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.10.2-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39136"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.11.4-2.el5_4.1" test_ref="oval:org.mitre.oval:tst:39024"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11098" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4134"/>
        <description>Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:29.140-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:30.426-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:07.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11098 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:35.791-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:30.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="star is earlier than 0:1.5a08-5" test_ref="oval:org.mitre.oval:tst:35154"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="star is earlier than 0:1.5a25-8" test_ref="oval:org.mitre.oval:tst:34243"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="star is earlier than 0:1.5a75-2" test_ref="oval:org.mitre.oval:tst:34991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11097" version="5" class="vulnerability">
      <metadata>
        <title>Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2262"/>
        <description>Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:11.330-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:30.228-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:07.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11097 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:26.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:29.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11093" version="5" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1773"/>
        <description>Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:10.690-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:29.533-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:06.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11093 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:26.394-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:28.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-16.2" test_ref="oval:org.mitre.oval:tst:31587"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="sharutils is earlier than 0:4.2.1-22.2" test_ref="oval:org.mitre.oval:tst:31528"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11092" version="5" class="vulnerability">
      <metadata>
        <title>The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0988"/>
        <description>The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:34.294-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:28.655-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:05.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11092 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:21.597-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:27.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11091" version="5" class="vulnerability">
      <metadata>
        <title>OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0395" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0395"/>
        <description>OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:54.795-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:26.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:03.444-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11091 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:03.299-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:25.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40734"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40777"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40693"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40128"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40760"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40400"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40127"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40611"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40762"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39852"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40397"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40779"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40506"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40652"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40384"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40416"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39970"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40764"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40757"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40750"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40647"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40730"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40460"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40680"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40656"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40735"/>
            <criterion comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40567"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40690"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39981"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40634"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40375"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40471"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40748"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40382"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40355"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39994"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40569"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40806"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40544"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40642"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40018"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40489"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40298"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39801"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40608"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40702"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40482"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40595"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40610"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40752"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40410"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40629"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40518"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40507"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:39822"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40613"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40769"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40288"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.1.el4_8.4" test_ref="oval:org.mitre.oval:tst:40778"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40536"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40230"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40632"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40739"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40728"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40741"/>
            <criterion comment="openoffice.org is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40522"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40718"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40407"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40113"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40685"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40740"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40733"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40742"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40583"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40420"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40691"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40334"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40447"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40590"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40383"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40394"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40568"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40599"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40411"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40036"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40346"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40708"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40499"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40678"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40579"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40121"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40688"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40768"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40321"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40621"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40618"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40713"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40633"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40649"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40041"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40191"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40457"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40412"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40594"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40659"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40478"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40715"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40571"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40614"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40681"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40623"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40463"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40587"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40454"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40602"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40564"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40612"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40051"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40578"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40575"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40707"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40662"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40585"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40091"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40650"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40531"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40205"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40774"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40434"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:39780"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40584"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:39884"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40706"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40472"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40645"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40692"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.5.el5_5.1" test_ref="oval:org.mitre.oval:tst:40388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11086" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4486"/>
        <description>Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:45.691-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:24.909-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:01.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11086 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:33.983-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:23.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32928"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32870"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32829"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32485"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32258"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32491"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32860"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32985"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32962"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32808"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32175"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32788"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33059"/>
            <criterion comment="php is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32754"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32876"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33047"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32483"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33052"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32964"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32700"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32272"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11084" version="5" class="vulnerability">
      <metadata>
        <title>PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue.  NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1490" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1490"/>
        <description>PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue.  NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:47.600-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:24.182-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:08:00.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11084 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:11.970-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:22.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32579"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32613"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32711"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32425"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32166"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32107"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32695"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31742"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32509"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32606"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32503"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32185"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32639"/>
            <criterion comment="php is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32546"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32577"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32236"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32578"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32591"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32707"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32547"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11082" version="5" class="vulnerability">
      <metadata>
        <title>OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2198"/>
        <description>OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:45.260-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:23.521-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:59.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11082 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:23.296-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:21.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32211"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:32773"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.2.0.EL3" test_ref="oval:org.mitre.oval:tst:31834"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32763"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32657"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32835"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-34.6.0.EL4" test_ref="oval:org.mitre.oval:tst:32791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11081" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1046"/>
        <description>Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:08.164-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:23.325-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:59.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11081 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:09.187-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:21.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdelibs is earlier than 6:3.3.1-3.10" test_ref="oval:org.mitre.oval:tst:31670"/>
          <criterion comment="kdelibs-devel is earlier than 6:3.3.1-3.10" test_ref="oval:org.mitre.oval:tst:31753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11080" version="5" class="vulnerability">
      <metadata>
        <title>The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838"/>
        <description>The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:25.004-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:22.776-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:59.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11080 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:42.859-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:20.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11078" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1233"/>
        <description>Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:01.629-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:21.996-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:58.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11078 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:31.792-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:19.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11077" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6504"/>
        <description>Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:51.318-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:21.488-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:57.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11077 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:54.549-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:19.099-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32785"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33227"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33266"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33146"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32352"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33183"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33095"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:32996"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el3" test_ref="oval:org.mitre.oval:tst:33263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33195"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33229"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32844"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33273"/>
            <criterion comment="seamonkey is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33259"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33239"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.6.el4" test_ref="oval:org.mitre.oval:tst:33284"/>
            <criterion comment="firefox is earlier than 0:1.5.0.9-0.1.el4" test_ref="oval:org.mitre.oval:tst:32815"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33153"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33015"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33251"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:33336"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32408"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11075" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0304"/>
        <description>Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:42.281-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:21.009-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:57.320-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11075 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:23:58.786-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:18.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11074" version="5" class="vulnerability">
      <metadata>
        <title>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0058"/>
        <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:48.506-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:20.716-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:56.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11074 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:26.762-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:17.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.12.11-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:32623"/>
            <criterion comment="sendmail-doc is earlier than 0:8.12.11-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:32643"/>
            <criterion comment="sendmail-cf is earlier than 0:8.12.11-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:31735"/>
            <criterion comment="sendmail-devel is earlier than 0:8.12.11-4.RHEL3.4" test_ref="oval:org.mitre.oval:tst:32467"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="sendmail is earlier than 0:8.13.1-3.RHEL4.3" test_ref="oval:org.mitre.oval:tst:32556"/>
            <criterion comment="sendmail-doc is earlier than 0:8.13.1-3.RHEL4.3" test_ref="oval:org.mitre.oval:tst:32379"/>
            <criterion comment="sendmail-cf is earlier than 0:8.13.1-3.RHEL4.3" test_ref="oval:org.mitre.oval:tst:32409"/>
            <criterion comment="sendmail-devel is earlier than 0:8.13.1-3.RHEL4.3" test_ref="oval:org.mitre.oval:tst:31921"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11072" version="5" class="vulnerability">
      <metadata>
        <title>gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1705"/>
        <description>gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:09.762-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:19.664-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:55.839-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11072 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:08.973-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:17.497-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gdb is earlier than 0:6.3.0.0-1.62" test_ref="oval:org.mitre.oval:tst:29887"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gdb is earlier than 0:6.3.0.0-1.63" test_ref="oval:org.mitre.oval:tst:32136"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11070" version="5" class="vulnerability">
      <metadata>
        <title>protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026"/>
        <description>protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:47.251-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:19.005-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:55.176-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11070 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:38.766-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:16.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39474"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39423"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39307"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39264"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39332"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39395"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39376"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39381"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el4" test_ref="oval:org.mitre.oval:tst:39450"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="finch-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39246"/>
            <criterion comment="libpurple is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39428"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39414"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39006"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:38683"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39404"/>
            <criterion comment="finch is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39139"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39341"/>
            <criterion comment="pidgin is earlier than 0:2.6.2-2.el5" test_ref="oval:org.mitre.oval:tst:39169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11067" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3472"/>
        <description>Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:03.082-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:18.086-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:54.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11067 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:23:57.866-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:15.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36386"/>
            <criterion comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:36408"/>
            <criterion comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" test_ref="oval:org.mitre.oval:tst:35731"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36297"/>
            <criterion comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36448"/>
            <criterion comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35759"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11066" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:06.477-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:17.530-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:53.625-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11066 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:37.656-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:14.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11065" version="5" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2788"/>
        <description>Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:43.949-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:16.958-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:53.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11065 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:30.818-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:14.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11063" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5015"/>
        <description>Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:53.319-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:16.369-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:51.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11063 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:21.761-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:13.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11062" version="5" class="vulnerability">
      <metadata>
        <title>scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4020"/>
        <description>scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:29.467-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:15.855-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:51.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11062 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:59.996-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:12.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32928"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32870"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32829"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32485"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32258"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32491"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-36.ent" test_ref="oval:org.mitre.oval:tst:32860"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32985"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32962"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32808"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32175"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32788"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33059"/>
            <criterion comment="php is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32754"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32876"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33047"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32483"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:33052"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32964"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32700"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.18" test_ref="oval:org.mitre.oval:tst:32272"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11061" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4933"/>
        <description>Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:11.293-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:15.378-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:50.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11061 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:06.938-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:11.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37830"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37968"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37984"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37633"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37352"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38043"/>
            <criterion comment="kernel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37989"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37908"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37748"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:37825"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" test_ref="oval:org.mitre.oval:tst:38002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37732"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38060"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38354"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38313"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38198"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37887"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38174"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38191"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38124"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38417"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:37779"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" test_ref="oval:org.mitre.oval:tst:38257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11060" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3245"/>
        <description>Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:04.521-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:15.137-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:50.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11060 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:59.452-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:11.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11059" version="5" class="vulnerability">
      <metadata>
        <title>socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666"/>
        <description>socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:53.233-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:14.835-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:50.253-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11059 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:47.336-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:10.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.0-3.el3.5" test_ref="oval:org.mitre.oval:tst:38901"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39046"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="fetchmail is earlier than 0:6.3.6-1.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:39380"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11058" version="5" class="vulnerability">
      <metadata>
        <title>MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3780"/>
        <description>MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:58.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:14.532-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:49.869-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11058 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:14.527-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:10.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:4.1.20-2.RHEL4.1.0.1" test_ref="oval:org.mitre.oval:tst:35230"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.20-2.RHEL4.1.0.1" test_ref="oval:org.mitre.oval:tst:34993"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.20-2.RHEL4.1.0.1" test_ref="oval:org.mitre.oval:tst:34731"/>
            <criterion comment="mysql-server is earlier than 0:4.1.20-2.RHEL4.1.0.1" test_ref="oval:org.mitre.oval:tst:34256"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mysql is earlier than 0:5.0.22-2.1.0.1" test_ref="oval:org.mitre.oval:tst:35229"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.22-2.1.0.1" test_ref="oval:org.mitre.oval:tst:34268"/>
            <criterion comment="mysql-test is earlier than 0:5.0.22-2.1.0.1" test_ref="oval:org.mitre.oval:tst:34271"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.22-2.1.0.1" test_ref="oval:org.mitre.oval:tst:34535"/>
            <criterion comment="mysql-server is earlier than 0:5.0.22-2.1.0.1" test_ref="oval:org.mitre.oval:tst:35148"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11057" version="5" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228"/>
        <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:42.949-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:14.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:49.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11057 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:53.081-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:10.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-12.rhel3" test_ref="oval:org.mitre.oval:tst:30880"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="gzip is earlier than 0:1.3.3-15.rhel4" test_ref="oval:org.mitre.oval:tst:31566"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11054" version="5" class="vulnerability">
      <metadata>
        <title>The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037"/>
        <description>The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:59.987-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:13.739-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:48.999-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11054 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:47.694-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:09.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="curl-devel is earlier than 0:7.10.6-9.rhel3" test_ref="oval:org.mitre.oval:tst:38524"/>
            <criterion comment="curl is earlier than 0:7.10.6-9.rhel3" test_ref="oval:org.mitre.oval:tst:37776"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" test_ref="oval:org.mitre.oval:tst:38532"/>
            <criterion comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" test_ref="oval:org.mitre.oval:tst:38496"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" test_ref="oval:org.mitre.oval:tst:38443"/>
            <criterion comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" test_ref="oval:org.mitre.oval:tst:38312"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11053" version="5" class="vulnerability">
      <metadata>
        <title>The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5500"/>
        <description>The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:04.718-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:13.115-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:48.312-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11053 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:25.208-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:08.384-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11052" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0176"/>
        <description>Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:01.337-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:12.598-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:47.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11052 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:28.661-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:07.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11050" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2950" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2950"/>
        <description>Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:04.502-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:10.512-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:45.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11050 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:05.178-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:05.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-46.2.0.EL3" test_ref="oval:org.mitre.oval:tst:40232"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-46.2.0.EL3" test_ref="oval:org.mitre.oval:tst:39552"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-46.2.0.EL3" test_ref="oval:org.mitre.oval:tst:39893"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39898"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39574"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40086"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39814"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39321"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40079"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40187"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40069"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40280"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39823"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39422"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.7.EL4.3" test_ref="oval:org.mitre.oval:tst:39760"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.7.EL4.3" test_ref="oval:org.mitre.oval:tst:40078"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40135"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40217"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39726"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40076"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39500"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40206"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39998"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40006"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39847"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39962"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39762"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40163"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39819"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39506"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40275"/>
            <criterion comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40058"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40104"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39977"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40138"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40155"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40266"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40024"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40188"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40123"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39776"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40262"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39872"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39958"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40178"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39976"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40092"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39695"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40167"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39830"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.7.EL4.3" test_ref="oval:org.mitre.oval:tst:40242"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39851"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39818"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40038"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.7.EL4.3" test_ref="oval:org.mitre.oval:tst:40279"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39959"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40197"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40245"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39845"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39936"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39966"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39879"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40025"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39786"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:40213"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.1.el4_8.3" test_ref="oval:org.mitre.oval:tst:39767"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40143"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40027"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39796"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39900"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40033"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39999"/>
            <criterion comment="openoffice.org is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39861"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39384"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39209"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40293"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40186"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40207"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39941"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39835"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39870"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40043"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40061"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40019"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39923"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40169"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39889"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39388"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40015"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39455"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40278"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39903"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39905"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39522"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40195"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39480"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40157"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39989"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39975"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40101"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39119"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39682"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39653"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39800"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40203"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40119"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40002"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39764"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39979"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39996"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40060"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40192"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39688"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39612"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39939"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39687"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40190"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39972"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39792"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39914"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39723"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40100"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40158"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39416"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39496"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39922"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40120"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39301"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40236"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40042"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39239"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40048"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39842"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39995"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39641"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39754"/>
            <criterion comment="openoffice.org-headless is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40170"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39951"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40166"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40110"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40223"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:40173"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.11.el5_4.4" test_ref="oval:org.mitre.oval:tst:39745"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11048" version="5" class="vulnerability">
      <metadata>
        <title>bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1995" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1995"/>
        <description>bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:20.816-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:09.953-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:44.931-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11048 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:34.719-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:04.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="quagga is earlier than 0:0.96.2-12.3E" test_ref="oval:org.mitre.oval:tst:34316"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="quagga-devel is earlier than 0:0.98.3-2.4.0.1.el4" test_ref="oval:org.mitre.oval:tst:34117"/>
            <criterion comment="quagga is earlier than 0:0.98.3-2.4.0.1.el4" test_ref="oval:org.mitre.oval:tst:34370"/>
            <criterion comment="quagga-contrib is earlier than 0:0.98.3-2.4.0.1.el4" test_ref="oval:org.mitre.oval:tst:34203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="quagga-devel is earlier than 0:0.98.6-2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34212"/>
            <criterion comment="quagga is earlier than 0:0.98.6-2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34264"/>
            <criterion comment="quagga-contrib is earlier than 0:0.98.6-2.1.0.1.el5" test_ref="oval:org.mitre.oval:tst:34361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11046" version="5" class="vulnerability">
      <metadata>
        <title>The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0720"/>
        <description>The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:58.340-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:09.423-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:44.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11046 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:58.535-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:03.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.42" test_ref="oval:org.mitre.oval:tst:33418"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.42" test_ref="oval:org.mitre.oval:tst:33293"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.42" test_ref="oval:org.mitre.oval:tst:33872"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.18" test_ref="oval:org.mitre.oval:tst:33504"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.18" test_ref="oval:org.mitre.oval:tst:33974"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.18" test_ref="oval:org.mitre.oval:tst:33999"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.5.1.el5" test_ref="oval:org.mitre.oval:tst:33766"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.5.1.el5" test_ref="oval:org.mitre.oval:tst:33927"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.5.1.el5" test_ref="oval:org.mitre.oval:tst:33887"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.5.1.el5" test_ref="oval:org.mitre.oval:tst:33961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11045" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6429"/>
        <description>Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:20.712-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:08.478-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:43.334-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11045 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:32.588-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:02.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35923"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35665"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36014"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35929"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36011"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35836"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35726"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35715"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35610"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36025"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35789"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35804"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35865"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35793"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35903"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35965"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35922"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35504"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35045"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35914"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35831"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35998"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35975"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36031"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35971"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35711"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35933"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35826"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35753"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35678"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35795"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35934"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35467"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35946"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36116"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35116"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36004"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35483"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36103"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36060"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36074"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35895"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35905"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36012"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35984"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35857"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35681"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35517"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35690"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35399"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35908"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35987"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35861"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11043" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609"/>
        <description>Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:23.242-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:07.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:41.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11043 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:39.176-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:11:01.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:39543"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40032"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40389"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40303"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40329"/>
            <criterion comment="tetex-doc is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40150"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.19" test_ref="oval:org.mitre.oval:tst:40000"/>
            <criterion comment="xpdf is earlier than 1:2.02-17.el3" test_ref="oval:org.mitre.oval:tst:39361"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39430"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39290"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38854"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39346"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" test_ref="oval:org.mitre.oval:tst:39383"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:38836"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-11.el5_4.3" test_ref="oval:org.mitre.oval:tst:39511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11040" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5508" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5508"/>
        <description>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:16.413-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:05.963-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:40.527-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11040 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:41.124-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:59.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:37631"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38114"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37737"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11038" version="5" class="vulnerability">
      <metadata>
        <title>Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2136"/>
        <description>Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:53.457-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:05.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:39.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11038 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:37.260-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:58.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37193"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37447"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37178"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37392"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37398"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37465"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37240"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37091"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37431"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37233"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.22.EL" test_ref="oval:org.mitre.oval:tst:37493"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36537"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36954"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37079"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:36957"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37527"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37262"/>
            <criterion comment="kernel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37410"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37323"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37508"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37153"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37180"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-92.1.10.el5" test_ref="oval:org.mitre.oval:tst:37188"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11037" version="5" class="vulnerability">
      <metadata>
        <title>Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1528"/>
        <description>Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:09.741-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:04.710-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:39.166-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11037 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:43.453-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:57.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11036" version="5" class="vulnerability">
      <metadata>
        <title>sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1517" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1517"/>
        <description>sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:34.848-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:04.484-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:38.819-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11036 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:34.113-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:57.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11035" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0754"/>
        <description>PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:55.309-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:03.735-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:38.010-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11035 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:02:18.924-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:56.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:38010"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37683"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37468"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37994"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37569"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37746"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-51.ent" test_ref="oval:org.mitre.oval:tst:37938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38324"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38288"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38029"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:37974"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38154"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38499"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38401"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38018"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38505"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38494"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38075"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38387"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38058"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.15" test_ref="oval:org.mitre.oval:tst:38202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38147"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38305"/>
            <criterion comment="php-common is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38268"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38298"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37882"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37952"/>
            <criterion comment="php is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38099"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38415"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38511"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38115"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38367"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38569"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38440"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38536"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38507"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38316"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38493"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:37667"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" test_ref="oval:org.mitre.oval:tst:38421"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11034" version="5" class="vulnerability">
      <metadata>
        <title>PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSIONs:39:".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1701"/>
        <description>PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:17.534-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:02.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:37.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11034 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:29.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:55.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33459"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33371"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33748"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33090"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33419"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33665"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-39.ent" test_ref="oval:org.mitre.oval:tst:33475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33282"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33636"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33548"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33156"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33407"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33562"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33500"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33725"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33105"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33501"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33691"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33662"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33087"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.3" test_ref="oval:org.mitre.oval:tst:33640"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11032" version="5" class="vulnerability">
      <metadata>
        <title>The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3353"/>
        <description>The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:06.485-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:02.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:36.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11032 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:00:53.598-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:54.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32105"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32433"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32429"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32322"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32301"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32253"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-26.ent" test_ref="oval:org.mitre.oval:tst:32050"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32261"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32003"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32346"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32114"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32325"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32420"/>
            <criterion comment="php is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32337"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32287"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32016"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32405"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32397"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32321"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:32207"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.9" test_ref="oval:org.mitre.oval:tst:31926"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11031" version="5" class="vulnerability">
      <metadata>
        <title>The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2492"/>
        <description>The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:46.620-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:02.055-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:36.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11031 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:25.194-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:54.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31896"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31885"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31861"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31550"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31914"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:31924"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.EL" test_ref="oval:org.mitre.oval:tst:32023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11030" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1939"/>
        <description>Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:43.949-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:01.779-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:35.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11030 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:53:00.583-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:01:53.739-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:53.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11029" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6352"/>
        <description>Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:28.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:01.525-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:35.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11029 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:27.417-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:53.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:35881"/>
            <criterion comment="libexif is earlier than 0:0.5.12-5.1.0.2.el4_6.1" test_ref="oval:org.mitre.oval:tst:35851"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35024"/>
            <criterion comment="libexif is earlier than 0:0.6.13-4.0.2.el5_1.1" test_ref="oval:org.mitre.oval:tst:35823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11028" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.4 has unknown impact and attack vectors, related to an "Improved fix for MOPB-03-2007," probably a variant of CVE-2007-1285.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4670"/>
        <description>Unspecified vulnerability in PHP before 5.2.4 has unknown impact and attack vectors, related to an "Improved fix for MOPB-03-2007," probably a variant of CVE-2007-1285.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:38.467-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:07:00.738-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:34.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11028 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:55.476-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:52.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35216"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35012"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34787"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35164"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34818"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:35171"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-43.ent" test_ref="oval:org.mitre.oval:tst:34820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35008"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34796"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35363"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35010"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35249"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34683"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34365"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:34976"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35087"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35298"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35289"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35309"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35263"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.9" test_ref="oval:org.mitre.oval:tst:35044"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35279"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34964"/>
            <criterion comment="php-common is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34896"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35084"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35078"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34802"/>
            <criterion comment="php is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35270"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35361"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34769"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35108"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35037"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34943"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34689"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35221"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35077"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34934"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:35170"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34376"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-15.el5" test_ref="oval:org.mitre.oval:tst:34764"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11025" version="5" class="vulnerability">
      <metadata>
        <title>The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5770"/>
        <description>The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:07.308-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:59.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:33.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11025 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:14.808-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:51.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35449"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35355"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35320"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35295"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35444"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:35440"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.EL4.8.1" test_ref="oval:org.mitre.oval:tst:34852"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35269"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35003"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:34553"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35433"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:34894"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35159"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35370"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35472"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_1.1" test_ref="oval:org.mitre.oval:tst:35510"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11024" version="5" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1466"/>
        <description>Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:14.296-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:59.639-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:33.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11024 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:50.481-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:50.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11019" version="5" class="vulnerability">
      <metadata>
        <title>The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720"/>
        <description>The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:41.785-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:58.615-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:31.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11019 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:45.643-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:49.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="expat is earlier than 0:1.95.5-6.2" test_ref="oval:org.mitre.oval:tst:39654"/>
            <criterion comment="expat-devel is earlier than 0:1.95.5-6.2" test_ref="oval:org.mitre.oval:tst:39129"/>
            <criterion comment="4Suite is earlier than 0:0.11.1-15" test_ref="oval:org.mitre.oval:tst:39666"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="expat is earlier than 0:1.95.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:39733"/>
            <criterion comment="PyXML is earlier than 0:0.8.3-6.el4_8.2" test_ref="oval:org.mitre.oval:tst:39810"/>
            <criterion comment="expat-devel is earlier than 0:1.95.7-4.el4_8.2" test_ref="oval:org.mitre.oval:tst:39660"/>
            <criterion comment="4Suite is earlier than 0:1.0-3.el4_8.1" test_ref="oval:org.mitre.oval:tst:39576"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="expat is earlier than 0:1.95.8-8.3.el5_4.2" test_ref="oval:org.mitre.oval:tst:39521"/>
            <criterion comment="PyXML is earlier than 0:0.8.4-4.el5_4.2" test_ref="oval:org.mitre.oval:tst:39204"/>
            <criterion comment="expat-devel is earlier than 0:1.95.8-8.3.el5_4.2" test_ref="oval:org.mitre.oval:tst:39647"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11018" version="5" class="vulnerability">
      <metadata>
        <title>The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3889" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3889"/>
        <description>The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:37.834-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:58.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:30.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11018 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:40.542-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:48.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39984"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40053"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39873"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39932"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39894"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39858"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40016"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39833"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39555"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39325"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40011"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40050"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39464"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39090"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40063"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39443"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39703"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39080"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39862"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40057"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40029"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39849"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11017" version="5" class="vulnerability">
      <metadata>
        <title>The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1285"/>
        <description>The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:32.075-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:57.264-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:29.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11017 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:09:00.458-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:47.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33776"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33817"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33769"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33528"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33915"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33822"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-40.ent" test_ref="oval:org.mitre.oval:tst:33351"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:34016"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33395"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33957"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33405"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33642"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33024"/>
            <criterion comment="php is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33690"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33995"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33892"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33945"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33711"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33857"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33644"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.22.4" test_ref="oval:org.mitre.oval:tst:33920"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:32784"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33240"/>
            <criterion comment="php-common is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33527"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33617"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33561"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33385"/>
            <criterion comment="php is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33615"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33526"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33747"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33735"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33403"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33686"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33502"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33666"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33508"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33652"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33676"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33784"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-7.el5" test_ref="oval:org.mitre.oval:tst:33706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11016" version="5" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:01.864-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:56.728-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:29.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11016 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:25.731-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:47.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:30819"/>
            <criterion comment="mozilla is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31515"/>
            <criterion comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31278"/>
            <criterion comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31465"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31606"/>
            <criterion comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31480"/>
            <criterion comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31417"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31313"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31469"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" test_ref="oval:org.mitre.oval:tst:31598"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30665"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31499"/>
            <criterion comment="mozilla is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31604"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31381"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31622"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:30651"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.3" test_ref="oval:org.mitre.oval:tst:31560"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31110"/>
            <criterion comment="evolution is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31003"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31404"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31375"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31106"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" test_ref="oval:org.mitre.oval:tst:31418"/>
            <criterion comment="evolution-devel is earlier than 0:2.0.2-14" test_ref="oval:org.mitre.oval:tst:31558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11015" version="5" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2710"/>
        <description>Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:47.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:56.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:29.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11015 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:04.630-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:46.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" test_ref="oval:org.mitre.oval:tst:31952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11014" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5959" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5959"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:32.803-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:55.961-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:28.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11014 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:07:32.728-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:45.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11013" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3812"/>
        <description>Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:45.554-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:55.488-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:28.061-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11013 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:34.420-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:44.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11012" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement.  NOTE: this issue is due to an incorrect patch for CVE-2007-1536.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2799"/>
        <description>Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement.  NOTE: this issue is due to an incorrect patch for CVE-2007-1536.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:14.321-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:55.264-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:27.778-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11012 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:17.705-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:44.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="file is earlier than 0:4.10-3.0.2.el4" test_ref="oval:org.mitre.oval:tst:34414"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="file is earlier than 0:4.17-9.0.1.el5" test_ref="oval:org.mitre.oval:tst:33605"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11011" version="5" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6103"/>
        <description>Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:23.417-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:54.446-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:26.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11011 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:58.559-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:43.407-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33279"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33033"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33135"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32975"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33134"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32756"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33026"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33238"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33343"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32868"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33217"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33260"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33106"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33262"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33329"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32993"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33159"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33053"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33163"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33308"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32484"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33294"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33176"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32802"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32909"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33270"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33234"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33180"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32796"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33158"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33322"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33297"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33211"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33206"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33346"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33222"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33340"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33228"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33187"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33289"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33242"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33068"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33283"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33337"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:32984"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33352"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33122"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11010" version="5" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3393"/>
        <description>Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:48.870-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:54.113-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:26.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11010 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:02:00.876-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:08:22.181-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:42.876-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34755"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34881"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34336"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34784"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11009" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1690"/>
        <description>Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:16.970-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:53.805-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:26.252-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11009 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:13:57.416-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:42.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:37977"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" test_ref="oval:org.mitre.oval:tst:38299"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38102"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38389"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" test_ref="oval:org.mitre.oval:tst:38720"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11007" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339.  NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4340"/>
        <description>Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339.  NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:46.381-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:53.315-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:25.700-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11007 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:00.262-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:41.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32910"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11006" version="5" class="vulnerability">
      <metadata>
        <title>Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5745"/>
        <description>Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:12.572-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:51.339-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:23.659-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11006 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:14:18.219-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:39.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36006"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35494"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36190"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36501"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35931"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36114"/>
            <criterion comment="openoffice.org2-draw is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36163"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36172"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36000"/>
            <criterion comment="openoffice.org2-base is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36287"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36118"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36384"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36302"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35683"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36473"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36223"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36224"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36154"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36091"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35963"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36083"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36271"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35954"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35495"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36299"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36417"/>
            <criterion comment="openoffice.org2 is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35864"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35957"/>
            <criterion comment="openoffice.org2-impress is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36286"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36345"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36181"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35811"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35640"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36248"/>
            <criterion comment="openoffice.org2-calc is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36212"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36434"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36159"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36411"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36382"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36148"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36144"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36401"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36185"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36254"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36289"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36009"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36216"/>
            <criterion comment="openoffice.org2-testtools is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36498"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36314"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36332"/>
            <criterion comment="openoffice.org2-core is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36253"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35829"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36429"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36073"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:35502"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36174"/>
            <criterion comment="openoffice.org2-math is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36366"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36276"/>
            <criterion comment="openoffice.org2-writer is earlier than 0:2.0.4-5.7.0.4.0" test_ref="oval:org.mitre.oval:tst:36057"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36162"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36101"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35841"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36520"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36441"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35845"/>
            <criterion comment="openoffice.org is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36307"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36505"/>
            <criterion comment="openoffice.org-writer is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36145"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36546"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36168"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36283"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36322"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36206"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36244"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36471"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36483"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36328"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35810"/>
            <criterion comment="openoffice.org-javafilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36481"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36465"/>
            <criterion comment="openoffice.org-testtools is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36378"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36013"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36191"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35521"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36257"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35797"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36391"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36398"/>
            <criterion comment="openoffice.org-base is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36329"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36437"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36130"/>
            <criterion comment="openoffice.org-core is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35843"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36220"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36466"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36032"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36187"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36058"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36160"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36457"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36341"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36232"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36089"/>
            <criterion comment="openoffice.org-pyuno is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36514"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36486"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36508"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36507"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36348"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36559"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36282"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36405"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36492"/>
            <criterion comment="openoffice.org-draw is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36369"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36308"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36358"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35561"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36070"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36189"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35657"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36204"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36544"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36218"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36400"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36037"/>
            <criterion comment="openoffice.org-calc is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35732"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36117"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36303"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36306"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35966"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36467"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35570"/>
            <criterion comment="openoffice.org-math is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36376"/>
            <criterion comment="openoffice.org-impress is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:36339"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 0:2.0.4-5.4.26" test_ref="oval:org.mitre.oval:tst:35999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11005" version="5" class="vulnerability">
      <metadata>
        <title>The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0017"/>
        <description>The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:34:48.212-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:50.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:22.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11005 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:10.650-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:38.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11004" version="5" class="vulnerability">
      <metadata>
        <title>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975"/>
        <description>PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:00.511-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:49.972-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:22.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11004 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:43.153-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:37.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40486"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40521"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40292"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40516"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40066"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40399"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40512"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40314"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40428"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40366"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.29-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:40465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="postgresql84-server is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40291"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40396"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40193"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40369"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40555"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40294"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40509"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40470"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40309"/>
            <criterion comment="postgresql is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40401"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40455"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40402"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40538"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40515"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:39839"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40452"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40505"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40251"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40108"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.21-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40253"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40257"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.4-1.el5_5.1" test_ref="oval:org.mitre.oval:tst:40379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11003" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0457"/>
        <description>Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:18.706-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:49.670-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:21.975-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11003 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:39.975-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:37.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-EL3.1" test_ref="oval:org.mitre.oval:tst:33506"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-EL3.1" test_ref="oval:org.mitre.oval:tst:33535"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-EL4.1" test_ref="oval:org.mitre.oval:tst:33380"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-EL4.1" test_ref="oval:org.mitre.oval:tst:33530"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="wireshark is earlier than 0:0.99.5-1.el5" test_ref="oval:org.mitre.oval:tst:33509"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.5-1.el5" test_ref="oval:org.mitre.oval:tst:33591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11002" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the X11 dissector in Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (divide-by-zero) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3248"/>
        <description>Unspecified vulnerability in the X11 dissector in Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (divide-by-zero) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:10.837-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:49.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:21.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11002 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:59.304-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:36.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11001" version="5" class="vulnerability">
      <metadata>
        <title>Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0207"/>
        <description>Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:12.695-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:49.163-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:21.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11001 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:09:00.343-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:12:38.706-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:36.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
          <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11000" version="5" class="vulnerability">
      <metadata>
        <title>The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4069"/>
        <description>The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:22.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:48.674-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:20.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11000 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:19:15.668-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:35.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10998" version="5" class="vulnerability">
      <metadata>
        <title>Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241"/>
        <description>The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:18.490-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:47.629-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:19.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10998 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:30.336-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:35.366-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" test_ref="oval:org.mitre.oval:tst:30954"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" test_ref="oval:org.mitre.oval:tst:31281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10997" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0996"/>
        <description>Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:17.079-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:47.185-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:19.393-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10997 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:56.286-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:34.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32579"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32613"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32711"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32425"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32166"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32107"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32695"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31742"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32509"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32606"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32503"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32185"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32639"/>
            <criterion comment="php is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32546"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32577"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32236"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32578"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32591"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32707"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32547"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10996" version="5" class="vulnerability">
      <metadata>
        <title>The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4035"/>
        <description>The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:35.153-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:46.913-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:19.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10996 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:06.002-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:34.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:39837"/>
          <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.6" test_ref="oval:org.mitre.oval:tst:39815"/>
          <criterion comment="xpdf is earlier than 1:3.00-23.el4_8.1" test_ref="oval:org.mitre.oval:tst:39216"/>
          <criterion comment="kdegraphics is earlier than 7:3.3.1-17.el4_8.1" test_ref="oval:org.mitre.oval:tst:38931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10994" version="5" class="vulnerability">
      <metadata>
        <title>libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2974" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2974"/>
        <description>libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:39.726-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:46.422-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:18.564-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10994 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:02.197-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:33.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:32066"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" test_ref="oval:org.mitre.oval:tst:31940"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libungif is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31956"/>
            <criterion comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:32398"/>
            <criterion comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" test_ref="oval:org.mitre.oval:tst:31871"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38143"/>
            <criterion comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38622"/>
            <criterion comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38639"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10993" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379"/>
        <description>Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:29:32.451-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:46.125-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:18.240-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10993 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:13.899-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:33.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-12.el3" test_ref="oval:org.mitre.oval:tst:39336"/>
            <criterion comment="libvorbis is earlier than 1:1.0-12.el3" test_ref="oval:org.mitre.oval:tst:39681"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.3" test_ref="oval:org.mitre.oval:tst:39730"/>
            <criterion comment="libvorbis is earlier than 1:1.1.0-3.el4_8.3" test_ref="oval:org.mitre.oval:tst:39644"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_4.4" test_ref="oval:org.mitre.oval:tst:39068"/>
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_4.4" test_ref="oval:org.mitre.oval:tst:39104"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10992" version="5" class="vulnerability">
      <metadata>
        <title>The ext3fs_dirhash function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via an ext3 stream with malformed data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6053"/>
        <description>The ext3fs_dirhash function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via an ext3 stream with malformed data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:32:24.689-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:45.773-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:17.895-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10992 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:25:12.532-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:32.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
          <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
        </criteria>
        <criteria operator="OR" comment="Configuration section">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10991" version="5" class="vulnerability">
      <metadata>
        <title>X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958"/>
        <description>X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:50.364-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:44.843-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:16.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10991 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:52:22.518-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:31.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35923"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35665"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36014"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35929"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36011"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35836"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35726"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35715"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35610"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36025"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35789"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35804"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35865"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35793"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35903"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35965"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35922"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35504"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35045"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35914"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35831"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35998"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35975"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:36031"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35971"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35711"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35933"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35826"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35753"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-126.EL" test_ref="oval:org.mitre.oval:tst:35678"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35795"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35934"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35467"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35946"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36116"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35116"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36004"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35483"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36103"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36060"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36074"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35895"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35905"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:36012"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35984"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35857"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35681"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" test_ref="oval:org.mitre.oval:tst:35909"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35517"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35690"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35399"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35908"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35987"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35861"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" test_ref="oval:org.mitre.oval:tst:35935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10990" version="5" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1198"/>
        <description>Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:58.396-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:44.219-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:16.239-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10990 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:44:00.892-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:53:08.673-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:30.691-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40598"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40703"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:39947"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40593"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40651"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:39843"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40800"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40736"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:39844"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.55.el3" test_ref="oval:org.mitre.oval:tst:40686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="firefox is earlier than 0:3.6.4-8.el4" test_ref="oval:org.mitre.oval:tst:40755"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:40296"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:39850"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:40624"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:40782"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:40431"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-58.el4_8" test_ref="oval:org.mitre.oval:tst:40449"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="gnome-python2-extras is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40435"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40552"/>
            <criterion comment="gnome-python2-libegg is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40721"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40480"/>
            <criterion comment="gnome-python2-gtkhtml2 is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40813"/>
            <criterion comment="totem is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40749"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.4-10.el5" test_ref="oval:org.mitre.oval:tst:40221"/>
            <criterion comment="gnome-python2-gtkspell is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40385"/>
            <criterion comment="yelp is earlier than 0:2.16.0-26.el5" test_ref="oval:org.mitre.oval:tst:40828"/>
            <criterion comment="devhelp is earlier than 0:0.12-21.el5" test_ref="oval:org.mitre.oval:tst:40814"/>
            <criterion comment="firefox is earlier than 0:3.6.4-8.el5" test_ref="oval:org.mitre.oval:tst:40524"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40620"/>
            <criterion comment="gnome-python2-gtkmozembed is earlier than 0:2.14.2-7.el5" test_ref="oval:org.mitre.oval:tst:40722"/>
            <criterion comment="esc is earlier than 0:1.1.0-12.el5" test_ref="oval:org.mitre.oval:tst:40273"/>
            <criterion comment="totem-devel is earlier than 0:2.16.7-7.el5" test_ref="oval:org.mitre.oval:tst:40637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10989" version="5" class="vulnerability">
      <metadata>
        <title>Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3080"/>
        <description>Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:31:40.931-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:43.678-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:15.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10989 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:24:40.390-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:30.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39984"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40053"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39873"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39932"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39894"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39858"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40016"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39833"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39555"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:39325"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.20.EL" test_ref="oval:org.mitre.oval:tst:40011"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40050"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39464"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39090"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40063"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39443"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39703"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39080"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39862"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40057"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40029"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:39849"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.11.1.el5" test_ref="oval:org.mitre.oval:tst:40039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10988" version="5" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347"/>
        <description>Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:33:13.633-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:43.382-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:15.338-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10988 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:15.943-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:29.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.5.7-33.el3" test_ref="oval:org.mitre.oval:tst:38552"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-33.el3" test_ref="oval:org.mitre.oval:tst:38921"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.6.1-12.el4_8.4" test_ref="oval:org.mitre.oval:tst:38786"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12.el4_8.4" test_ref="oval:org.mitre.oval:tst:38925"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_3.4" test_ref="oval:org.mitre.oval:tst:38773"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_3.4" test_ref="oval:org.mitre.oval:tst:37937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10987" version="5" class="vulnerability">
      <metadata>
        <title>PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1349"/>
        <description>PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:31.377-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:43.087-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:14.984-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10987 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:50.748-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:29.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mod_perl-devel is earlier than 0:1.99_09-12.ent" test_ref="oval:org.mitre.oval:tst:34145"/>
            <criterion comment="mod_perl is earlier than 0:1.99_09-12.ent" test_ref="oval:org.mitre.oval:tst:34220"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mod_perl-devel is earlier than 0:1.99_16-4.5" test_ref="oval:org.mitre.oval:tst:34277"/>
            <criterion comment="mod_perl is earlier than 0:1.99_16-4.5" test_ref="oval:org.mitre.oval:tst:34069"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="mod_perl-devel is earlier than 0:2.0.2-6.3.el5" test_ref="oval:org.mitre.oval:tst:34267"/>
            <criterion comment="mod_perl is earlier than 0:2.0.2-6.3.el5" test_ref="oval:org.mitre.oval:tst:34307"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10986" version="5" class="vulnerability">
      <metadata>
        <title>The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1579" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1579"/>
        <description>The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:30:13.366-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:42.762-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:14.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10986 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:44:34.931-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:28.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-13.el3" test_ref="oval:org.mitre.oval:tst:38027"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" test_ref="oval:org.mitre.oval:tst:38669"/>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" test_ref="oval:org.mitre.oval:tst:37946"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10985" version="5" class="vulnerability">
      <metadata>
        <title>Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involves a "malformed POSIX character class", as demonstrated via an invalid character after a [[ sequence.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7225"/>
        <description>Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involves a "malformed POSIX character class", as demonstrated via an invalid character after a [[ sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:47.952-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:42.521-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:14.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10985 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T17:18:00.939-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T17:23:59.588-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:28.195-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35615"/>
            <criterion comment="pcre is earlier than 0:4.5-4.el4_6.6" test_ref="oval:org.mitre.oval:tst:35501"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="pcre-devel is earlier than 0:6.6-2.el5_1.7" test_ref="oval:org.mitre.oval:tst:35251"/>
            <criterion comment="pcre is earlier than 0:6.6-2.el5_1.7" test_ref="oval:org.mitre.oval:tst:35032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10981" version="5" class="vulnerability">
      <metadata>
        <title>The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>CentOS Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>CentOS Linux 4</platform>
          <platform>Oracle Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>Oracle Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094"/>
        <description>The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:28:28.271-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:06:41.706-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:07:13.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:10981 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T16:31:00.815-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T16:43:34.841-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:10:26.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="OS Section: RHEL3, CentOS3">
          <criteria operator="OR" comment="RHEL3 or CentOS3">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
            <extend_definition comment="CentOS Linux 3.x" definition_ref="oval:org.mitre.oval:def:16651"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39637"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39671"/>
            <criterion comment="httpd is earlier than 0:2.0.46-77.ent" test_ref="oval:org.mitre.oval:tst:39611"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL4, CentOS4, Oracle Linux 4">
          <criteria operator="OR" comment="RHEL4, CentOS4 or Oracle Linux 4">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
            <extend_definition comment="CentOS Linux 4.x" definition_ref="oval:org.mitre.oval:def:16636"/>
            <extend_definition comment="Oracle Linux 4.x" definition_ref="oval:org.mitre.oval:def:15990"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39448"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39501"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:38802"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39716"/>
            <criterion comment="httpd is earlier than 0:2.0.52-41.ent.6" test_ref="oval:org.mitre.oval:tst:39551"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="OS Section: RHEL5, CentOS5, Oracle Linux 5">
          <criteria operator="OR" comment="RHEL5, CentOS5 or Oracle Linux 5">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
            <extend_definition comment="Oracle Linux 5.x" definition_ref="oval:org.mitre.oval:def:15459"/>
          </criteria>
          <criteria operator="OR" comment="Configuration section">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39267"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39640"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" test_ref="oval:org.mitre.oval:tst:39613"/>
            