<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:17:53</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20030334" version="301" class="patch">
      <metadata>
        <title>RHSA-2003:334: glibc security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2003:334-01" ref_url="https://rhn.redhat.com/errata/RHSA-2003-334.html"/>
	<description>The glibc packages contain GNU libc, which provides standard system libraries.

Herbert Xu reported that various applications can accept spoofed messages
sent on the kernel netlink interface by other users on the local machine.
This could lead to a local denial of service attack. The glibc function
getifaddrs uses netlink and could therefore be vulnerable to this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0859 to this issue.

In addition to the security issues, a number of other bugs were fixed.

Users are advised to upgrade to these erratum packages, which contain a
patch that checks that netlink messages actually came from the kernel
and patches for the various bug fixes.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2003 Red Hat, Inc.</rights>
        <issued date="2003-11-14"/>
        <updated date="2003-11-14"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0859">CVE-2003-0859</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20030334001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334002" comment="glibc is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334003" comment="glibc is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334004" comment="glibc-common is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334005" comment="glibc-common is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334006" comment="glibc-devel is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334007" comment="glibc-devel is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334008" comment="glibc-headers is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334009" comment="glibc-headers is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334010" comment="glibc-profile is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334011" comment="glibc-profile is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334012" comment="glibc-utils is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334013" comment="glibc-utils is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334014" comment="nptl-devel is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334015" comment="nptl-devel is signed with Red Hat master key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334016" comment="nscd is earlier than 0:2.3.2-95.6"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20030334017" comment="nscd is signed with Red Hat master key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhsa:tst:20030334001" version="301" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334001"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334002" version="301" comment="glibc is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334003" version="301" comment="glibc is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334004" version="301" comment="glibc-common is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334005" version="301" comment="glibc-common is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334006" version="301" comment="glibc-devel is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334007" version="301" comment="glibc-devel is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334008" version="301" comment="glibc-headers is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334009" version="301" comment="glibc-headers is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334010" version="301" comment="glibc-profile is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334011" version="301" comment="glibc-profile is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334012" version="301" comment="glibc-utils is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334007"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334013" version="301" comment="glibc-utils is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334007"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334014" version="301" comment="nptl-devel is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334008"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334015" version="301" comment="nptl-devel is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334008"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334016" version="301" comment="nscd is earlier than 0:2.3.2-95.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334009"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20030334017" version="301" comment="nscd is signed with Red Hat master key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20030334009"/>
<state state_ref="oval:com.redhat.rhsa:ste:20030334003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhsa:obj:20030334001" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334002" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334003" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc-common</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334004" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334005" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc-headers</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334006" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc-profile</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334007" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>glibc-utils</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334008" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>nptl-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20030334009" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>nscd</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhsa:ste:20030334001" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20030334002" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">0:2.3.2-95.6</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20030334003" version="301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>