<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:23:24
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20030315" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:315: quagga security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:315-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-315.html" />
	<description>Quagga is an open source implementation of TCP/IP routing software. 
 
Herbert Xu reported that Quagga can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to
this issue. 
 
Users of Quagga should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel. 
This erratum also includes quagga-devel and quagga-contrib packages which
were not originally shipped with Red Hat Enterprise Linux 3.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0858">CVE-2003-0858</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315002" comment="quagga is earlier than 0:0.96.2-8.3E" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315003" comment="quagga is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315004" comment="quagga-contrib is earlier than 0:0.96.2-8.3E" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315005" comment="quagga-contrib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315006" comment="quagga-devel is earlier than 0:0.96.2-8.3E" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030315007" comment="quagga-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030317" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:317: iproute security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:317-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-317.html" />
	<description>The iproute package contains advanced IP routing and network device
configuration tools.

Herbert Xu reported that iproute can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine.  This could
lead to a local denial of service attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0856 to
this issue. 
 
Users of iproute should upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0856">CVE-2003-0856</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030317002" comment="iproute is earlier than 0:2.4.7-11.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030317003" comment="iproute is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030324" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:324: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:324-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-324.html" />
	<description>Ethereal is a program for monitoring network traffic.

A number of security issues affect Ethereal.  By exploiting these issues,
it may be possible to make Ethereal crash or run arbitrary code by
injecting a purposefully-malformed packet onto the wire or by convincing
someone to read a malformed packet trace file.

A buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers
to cause a denial of service and possibly execute arbitrary code via a
malformed GTP MSISDN string.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2003-0925 to
this issue.

Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of
service (crash) via certain malformed ISAKMP or MEGACO packets.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0926 to this issue.

A heap-based buffer overflow in Ethereal 0.9.15 and earlier allows
remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code via the SOCKS dissector.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0927
to this issue.

Users of Ethereal should update to these erratum packages containing
Ethereal version 0.9.16, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-12" />
        <updated date="2003-11-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0925">CVE-2003-0925</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0926">CVE-2003-0926</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0927">CVE-2003-0927</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030324002" comment="ethereal is earlier than 0:0.9.16-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030324003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030324004" comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030324005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030334" version="301" class="patch">
      <metadata>
        <title>RHSA-2003:334: glibc security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:334-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-334.html" />
	<description>The glibc packages contain GNU libc, which provides standard system libraries.

Herbert Xu reported that various applications can accept spoofed messages
sent on the kernel netlink interface by other users on the local machine.
This could lead to a local denial of service attack. The glibc function
getifaddrs uses netlink and could therefore be vulnerable to this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0859 to this issue.

In addition to the security issues, a number of other bugs were fixed.

Users are advised to upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel
and patches for the various bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-14" />
        <updated date="2003-11-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0859">CVE-2003-0859</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334002" comment="glibc is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334004" comment="glibc-common is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334006" comment="glibc-devel is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334008" comment="glibc-headers is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-headers is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334010" comment="glibc-profile is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-profile is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334012" comment="glibc-utils is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334014" comment="nptl-devel is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="nptl-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334016" comment="nscd is earlier than 0:2.3.2-95.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030386" version="303" class="patch">
      <metadata>
        <title>RHSA-2003:386: freeradius security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:386-03" ref_url="https://rhn.redhat.com/errata/RHSA-2003-386.html" />
	<description>FreeRADIUS is an Internet authentication daemon, which implements the
RADIUS protocol.  It allows Network Access Servers (NAS boxes) to perform
authentication for dial-up users.

The rad_decode function in FreeRADIUS 0.9.2 and earlier allows remote
attackers to cause a denial of service (crash) via a short RADIUS string
attribute with a tag, which causes memcpy to be called with a -1 length
argument, as demonstrated using the Tunnel-Password attribute.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0967 to this issue.
 
Users of FreeRADIUS are advised to upgrade to these erratum packages
containing FreeRADIUS 0.9.3 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0967">CVE-2003-0967</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030386002" comment="freeradius is earlier than 0:0.9.3-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030386003" comment="freeradius is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030395" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:395: gnupg security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:395-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-395.html" />
	<description>GnuPG is a utility for encrypting data and creating digital signatures.

Phong Nguyen identified a severe bug in the way GnuPG creates and uses
ElGamal keys, when those keys are used both to sign and encrypt data.  This
vulnerability can be used to trivially recover the private key.  While the
default behavior of GnuPG when generating keys does not lead to the
creation of unsafe keys, by overriding the default settings an unsafe key
could have been created.

If you are using ElGamal keys, you should revoke those keys immediately.

The packages included in this update do not make ElGamal keys safe to use;
they merely include a patch by David Shaw that disables functions that
would generate or use ElGamal keys.

To determine if your key is affected, run the following command to obtain a
list of secret keys that you have on your secret keyring:

gpg --list-secret-keys

The output of this command includes both the size and type of the keys
found, and will look similar to this example:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024D/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

The key length, type, and ID are listed together, separated by a forward
slash.  In the example output above, the key's type is "D" (DSA, sign
and encrypt).  Your key is unsafe if and only if the key type is "G"
(ElGamal, sign and encrypt).  In the above example, the secret key is safe
to use, while the secret key in the following example is not:

/home/example/.gnupg/secring.gpg
----------------------------------------------------
sec  1024G/01234567 2000-10-17 Example User &lt;example@example.com>
uid                            Example User &lt;example@example.com>

For more details regarding this issue, as well as instructions on how to
revoke any keys that are unsafe, refer to the advisory available from the
GnuPG web site:

http://www.gnupg.org/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-10" />
        <updated date="2003-12-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0971">CVE-2003-0971</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030395002" comment="gnupg is earlier than 0:1.2.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030395003" comment="gnupg is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030399" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:399: rsync security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:399-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-399.html" />
	<description>rsync is a program for sychronizing files over the network.

A heap overflow bug exists in rsync versions prior to 2.5.7.  On machines
where the rsync server has been enabled, a remote attacker could use this
flaw to execute arbitrary code as an unprivileged user.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0962 to this issue.

All users should upgrade to these erratum packages containing version
2.5.7 of rsync, which is not vulnerable to this issue.

NOTE: The rsync server is disabled (off) by default in Red Hat Enterprise
Linux.  To check if the rsync server has been enabled (on), run the
following command:

/sbin/chkconfig --list rsync

If the rsync server has been enabled but is not required, it can be
disabled by running the following command as root:

/sbin/chkconfig rsync off

Red Hat would like to thank the rsync team for their rapid response and
quick fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-12-04" />
        <updated date="2003-12-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0962">CVE-2003-0962</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030399002" comment="rsync is earlier than 0:2.5.7-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030399003" comment="rsync is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030404" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:404: lftp security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:404-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-404.html" />
	<description>lftp is a command-line file transfer program supporting FTP and HTTP
protocols. 

Ulf Härnhammar discovered a buffer overflow bug in versions of lftp up to
and including 2.6.9.  An attacker could create a carefully crafted
directory on a website such that, if a user connects to that directory
using the lftp client and subsequently issues a 'ls' or 'rels' command, the
attacker could execute arbitrary code on the users machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0963 to this issue.

Users of lftp are advised to upgrade to these erratum packages, which
contain a backported security patch and are not vulnerable to this issue.

Red Hat would like to thank Ulf Härnhammar for discovering and alerting us
to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2003-12-16" />
        <updated date="2007-01-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0963">CVE-2003-0963</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030404002" comment="lftp is earlier than 0:2.6.3-5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030404003" comment="lftp is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20030416" version="302" class="patch">
      <metadata>
        <title>RHSA-2003:416: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:416-02" ref_url="https://rhn.redhat.com/errata/RHSA-2003-416.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux
kernel versions 2.4.23 and previous which may allow a local attacker to
gain root privileges.  No exploit is currently available; however, it is
believed that this issue is exploitable (although not trivially.) The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0985 to this issue.

All users of Red Hat Enterprise Linux 3 are advised to upgrade to these
errata packages, which contain a backported security patch that corrects
this issue.

Red Hat would like to thank Paul Starzetz from ISEC for disclosing this
issue as well as Andrea Arcangeli and Solar Designer for working on the patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-07" />
        <updated date="2004-01-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985">CVE-2003-0985</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030315001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416002" comment="kernel is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416004" comment="kernel-BOOT is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416005" comment="kernel-BOOT is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416006" comment="kernel-doc is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416007" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416008" comment="kernel-hugemem is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416009" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416010" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416011" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416012" comment="kernel-smp is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416013" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416014" comment="kernel-smp-unsupported is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416015" comment="kernel-smp-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416016" comment="kernel-source is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416017" comment="kernel-source is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416018" comment="kernel-unsupported is earlier than 0:2.4.21-4.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030416019" comment="kernel-unsupported is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
</definitions>

<tests>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315001" version="302" comment="redhat-release is version 3" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315001" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315002" version="302" comment="quagga is earlier than 0:0.96.2-8.3E" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315003" version="302" comment="quagga is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315004" version="302" comment="quagga-contrib is earlier than 0:0.96.2-8.3E" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315005" version="302" comment="quagga-contrib is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315006" version="302" comment="quagga-devel is earlier than 0:0.96.2-8.3E" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030315007" version="302" comment="quagga-devel is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030315004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030317002" version="302" comment="iproute is earlier than 0:2.4.7-11.30E.1" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030317002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030317002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030317003" version="302" comment="iproute is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030317002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030324002" version="302" comment="ethereal is earlier than 0:0.9.16-0.30E.1" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030324002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030324002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030324003" version="302" comment="ethereal is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030324002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030324004" version="302" comment="ethereal-gnome is earlier than 0:0.9.16-0.30E.1" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030324003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030324002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030324005" version="302" comment="ethereal-gnome is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030324003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334002" version="301" comment="glibc is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334003" version="301" comment="glibc is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334004" version="301" comment="glibc-common is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334005" version="301" comment="glibc-common is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334006" version="301" comment="glibc-devel is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334007" version="301" comment="glibc-devel is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334008" version="301" comment="glibc-headers is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334005" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334009" version="301" comment="glibc-headers is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334005" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334010" version="301" comment="glibc-profile is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334006" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334011" version="301" comment="glibc-profile is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334006" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334012" version="301" comment="glibc-utils is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334007" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334013" version="301" comment="glibc-utils is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334007" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334014" version="301" comment="nptl-devel is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334008" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334015" version="301" comment="nptl-devel is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334008" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334016" version="301" comment="nscd is earlier than 0:2.3.2-95.6" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334009" />
<state state_ref="oval:com.redhat.rhsa:ste:20030334002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030334017" version="301" comment="nscd is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030334009" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030386002" version="303" comment="freeradius is earlier than 0:0.9.3-1" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030386002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030386002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030386003" version="303" comment="freeradius is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030386002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030395002" version="302" comment="gnupg is earlier than 0:1.2.1-10" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030395002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030395002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030395003" version="302" comment="gnupg is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030395002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030399002" version="302" comment="rsync is earlier than 0:2.5.7-1" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030399002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030399002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030399003" version="302" comment="rsync is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030399002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030404002" version="302" comment="lftp is earlier than 0:2.6.3-5" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030404002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030404002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030404003" version="302" comment="lftp is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030404002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416002" version="302" comment="kernel is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416003" version="302" comment="kernel is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416002" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416004" version="302" comment="kernel-BOOT is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416005" version="302" comment="kernel-BOOT is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416003" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416006" version="302" comment="kernel-doc is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416007" version="302" comment="kernel-doc is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416004" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416008" version="302" comment="kernel-hugemem is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416005" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416009" version="302" comment="kernel-hugemem is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416005" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416010" version="302" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416006" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416011" version="302" comment="kernel-hugemem-unsupported is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416006" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416012" version="302" comment="kernel-smp is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416007" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416013" version="302" comment="kernel-smp is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416007" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416014" version="302" comment="kernel-smp-unsupported is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416008" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416015" version="302" comment="kernel-smp-unsupported is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416008" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416016" version="302" comment="kernel-source is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416009" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416017" version="302" comment="kernel-source is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416009" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416018" version="302" comment="kernel-unsupported is earlier than 0:2.4.21-4.0.2.EL" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416010" />
<state state_ref="oval:com.redhat.rhsa:ste:20030416002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20030416019" version="302" comment="kernel-unsupported is signed with Red Hat master key" check="at least one">
<object object_ref="oval:com.redhat.rhsa:obj:20030416010" />
<state state_ref="oval:com.redhat.rhsa:ste:20030315003" />
</rpminfo_test>
</tests>

<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030315001" version="302">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030315002" version="302">
  <name>quagga</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030315003" version="302">
  <name>quagga-contrib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030315004" version="302">
  <name>quagga-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030317002" version="302">
  <name>iproute</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030324002" version="302">
  <name>ethereal</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030324003" version="302">
  <name>ethereal-gnome</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334002" version="301">
  <name>glibc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334003" version="301">
  <name>glibc-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334004" version="301">
  <name>glibc-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334005" version="301">
  <name>glibc-headers</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334006" version="301">
  <name>glibc-profile</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334007" version="301">
  <name>glibc-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334008" version="301">
  <name>nptl-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030334009" version="301">
  <name>nscd</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030386002" version="303">
  <name>freeradius</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030395002" version="302">
  <name>gnupg</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030399002" version="302">
  <name>rsync</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030404002" version="302">
  <name>lftp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416002" version="302">
  <name>kernel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416003" version="302">
  <name>kernel-BOOT</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416004" version="302">
  <name>kernel-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416005" version="302">
  <name>kernel-hugemem</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416006" version="302">
  <name>kernel-hugemem-unsupported</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416007" version="302">
  <name>kernel-smp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416008" version="302">
  <name>kernel-smp-unsupported</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416009" version="302">
  <name>kernel-source</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20030416010" version="302">
  <name>kernel-unsupported</name>
</rpminfo_object>
</objects>

<states>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030315001" version="302">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030315002" version="302">
  <evr datatype="evr_string" operation="less than">0:0.96.2-8.3E</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030315003" version="302">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030317002" version="302">
  <evr datatype="evr_string" operation="less than">0:2.4.7-11.30E.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030324002" version="302">
  <evr datatype="evr_string" operation="less than">0:0.9.16-0.30E.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030334002" version="301">
  <evr datatype="evr_string" operation="less than">0:2.3.2-95.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030386002" version="303">
  <evr datatype="evr_string" operation="less than">0:0.9.3-1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030395002" version="302">
  <evr datatype="evr_string" operation="less than">0:1.2.1-10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030399002" version="302">
  <evr datatype="evr_string" operation="less than">0:2.5.7-1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030404002" version="302">
  <evr datatype="evr_string" operation="less than">0:2.6.3-5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20030416002" version="302">
  <evr datatype="evr_string" operation="less than">0:2.4.21-4.0.2.EL</evr>
</rpminfo_state>
</states>

</oval_definitions>
