<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:17:56</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20040015" version="305" class="patch">
      <metadata>
        <title>RHSA-2004:015: httpd security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2004:015-05" ref_url="https://rhn.redhat.com/errata/RHSA-2004-015.html"/>
	<description>The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue in the handling of regular expressions from configuration files
was discovered in releases of the Apache HTTP Server version 2.0 prior to
2.0.48. To exploit this issue an attacker would need to have the ability
to write to Apache configuration files such as .htaccess or httpd.conf. A
carefully-crafted configuration file can cause an exploitable buffer
overflow and would allow the attacker to execute arbitrary code in the
context of the server (in default configurations as the 'apache' user).
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0542 to this issue.

Users of the Apache HTTP Server should upgrade to these erratum packages,
which contain backported patches correcting these issues, and are applied
to Apache version 2.0.46.  This update also includes fixes for a number of
minor bugs found in this version of the Apache HTTP Server.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-01-13"/>
        <updated date="2004-01-13"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542">CVE-2003-0542</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20040015001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015002" comment="httpd is earlier than 0:2.0.46-26.ent"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015003" comment="httpd is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015004" comment="httpd-devel is earlier than 0:2.0.46-26.ent"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015005" comment="httpd-devel is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015006" comment="mod_ssl is earlier than 1:2.0.46-26.ent"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040015007" comment="mod_ssl is signed with Red Hat security key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhsa:tst:20040015001" version="305" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015001"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015002" version="305" comment="httpd is earlier than 0:2.0.46-26.ent" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015003" version="305" comment="httpd is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015004" version="305" comment="httpd-devel is earlier than 0:2.0.46-26.ent" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015005" version="305" comment="httpd-devel is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015006" version="305" comment="mod_ssl is earlier than 1:2.0.46-26.ent" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015004"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040015007" version="305" comment="mod_ssl is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040015004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040015003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhsa:obj:20040015001" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040015002" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>httpd</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040015003" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>httpd-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040015004" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mod_ssl</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhsa:ste:20040015001" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040015002" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">0:2.0.46-26.ent</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040015003" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040015004" version="305" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">1:2.0.46-26.ent</evr>
</rpminfo_state>

  </states>
</oval_definitions>