<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:17:51</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhba:def:20060287" version="302" class="patch">
      <metadata>
        <title>RHBA-2006:0287: bind bug fix update
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2006:0287-02" ref_url="https://rhn.redhat.com/errata/RHBA-2006-0287.html"/>
	<description>BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. The bind package provides a DNS server
(named), which resolves host names to IP addresses, and tools for 
control and verification of the DNS server. The bind-libs package
provides the libraries used by the DNS server and bind-utils. The
bind-utils package provides DNS lookup utilities: host(1), dig(1),
and nslookup. The bind-devel package provides header files for 
development with the BIND libraries. A default set of DNS server
configuration files is provided by the caching-nameserver package.

This update delivers backports from ISC BIND 9.2.6 to fix these issues:
--Fixes to named's thread locking logic

This feature in ISC BIND 9.3.0+ was backported and delivered in this update:
--edns-udp-size: Users can now set the maximum size of UDP packets used 
  for EDNS0 (RFC 2671), to get past routers / firewalls that enforce a
  maximum UDP packet size.

Miscellaneous bug fixes, including improved support for custom named.conf
locations, are also delivered in this update.

All BIND users are advised to upgrade to these updated bind packages.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2006 Red Hat, Inc.</rights>
        <issued date="2006-07-19"/>
        <updated date="2006-07-19"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4096">CVE-2006-4096</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20060287001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20060287002" comment="bind is earlier than 20:9.2.4-14_EL3"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20060287003" comment="bind is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20060287004" comment="bind-chroot is earlier than 20:9.2.4-14_EL3"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20060287005" comment="bind-chroot is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20060287006" comment="bind-devel is earlier than 20:9.2.4-14_EL3"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20060287007" comment="bind-devel is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20060287008" comment="bind-libs is earlier than 20:9.2.4-14_EL3"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20060287009" comment="bind-libs is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20060287010" comment="bind-utils is earlier than 20:9.2.4-14_EL3"/>
            <criterion test_ref="oval:com.redhat.rhba:tst:20060287011" comment="bind-utils is signed with Red Hat master key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhba:tst:20060287001" version="302" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287001"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287002" version="302" comment="bind is earlier than 20:9.2.4-14_EL3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287002"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287003" version="302" comment="bind is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287002"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287004" version="302" comment="bind-chroot is earlier than 20:9.2.4-14_EL3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287003"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287005" version="302" comment="bind-chroot is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287003"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287006" version="302" comment="bind-devel is earlier than 20:9.2.4-14_EL3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287004"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287007" version="302" comment="bind-devel is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287004"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287008" version="302" comment="bind-libs is earlier than 20:9.2.4-14_EL3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287005"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287009" version="302" comment="bind-libs is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287005"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287010" version="302" comment="bind-utils is earlier than 20:9.2.4-14_EL3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287006"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhba:tst:20060287011" version="302" comment="bind-utils is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhba:obj:20060287006"/>
<state state_ref="oval:com.redhat.rhba:ste:20060287003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhba:obj:20060287001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20060287002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>bind</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20060287003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>bind-chroot</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20060287004" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>bind-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20060287005" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>bind-libs</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhba:obj:20060287006" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>bind-utils</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhba:ste:20060287001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhba:ste:20060287002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">20:9.2.4-14_EL3</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhba:ste:20060287003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>