<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:17:50</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhba:def:20050447" version="302" class="patch">
      <metadata>
        <title>RHBA-2005:447: Updated cdrtools packages
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2005:447-02" ref_url="https://rhn.redhat.com/errata/RHBA-2005-447.html"/>
	<description>Cdrecord is an application for recording audio and data CDs. Cdrecord
works with many different brands of CD recorders, fully supports
multi-sessions, and provides human-readable error messages.

The cdrecord package on Red Hat Enterprise Linux does not require setuid
root for use by normal users.  The permissions of the writer device are
changed by pam_console_apply at console login.  Setting the uid of cdrecord
to root opens a vulnerability to possible exploitation.

All users of cdrecord that setuid root should upgrade to these updated
packages, which resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19"/>
        <updated date="2005-05-19"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0806">CVE-2004-0806</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447002" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.2"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447003" comment="cdrtools is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447004" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.2"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447005" comment="cdrecord is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447006" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.2"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447007" comment="cdrecord-devel is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447008" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.2"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447009" comment="mkisofs is signed with Red Hat master key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhba:tst:20050447001" version="302" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447001"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447002" version="302" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447002"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447003" version="302" comment="cdrtools is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447002"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447004" version="302" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447003"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447005" version="302" comment="cdrecord is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447003"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447006" version="302" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447004"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447007" version="302" comment="cdrecord-devel is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447004"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447008" version="302" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447005"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20050447009" version="302" comment="mkisofs is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20050447005"/>
<state state_ref="oval:com.redhat.rhba:ste:20050447003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhba:obj:20050447001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20050447002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>cdrtools</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20050447003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>cdrecord</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20050447004" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>cdrecord-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20050447005" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mkisofs</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhba:ste:20050447001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhba:ste:20050447002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">8:2.01.0.a32-0.EL3.2</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhba:ste:20050447003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>