<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:18:01</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20040110" version="303" class="patch">
      <metadata>
        <title>RHSA-2004:110: mozilla security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2004:110-03" ref_url="https://rhn.redhat.com/errata/RHSA-2004-110.html"/>
	<description>Mozilla is a Web browser and mail reader, designed for standards
compliance, performance and portability.  Network Security Services (NSS)
is a set of libraries designed to support cross-platform development of
security-enabled server applications. 

NISCC testing of implementations of the S/MIME protocol uncovered a number
of bugs in NSS versions prior to 3.9.   The parsing of unexpected ASN.1
constructs within S/MIME data could cause Mozilla to crash or consume large
amounts of memory.  A remote attacker could potentially trigger these bugs
by sending a carefully-crafted S/MIME message to a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0564 to this issue. 

Andreas Sandblad discovered a cross-site scripting issue that affects
various versions of Mozilla.  When linking to a new page it is still
possible to interact with the old page before the new page has been
successfully loaded. Any Javascript events will be invoked in the context
of the new page, making cross-site scripting possible if the different
pages belong to different domains.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0191 to
this issue. 

Flaws have been found in the cookie path handling between a number of Web
browsers and servers. The HTTP cookie standard allows a Web server
supplying a cookie to a client to specify a subset of URLs on the origin
server to which the cookie applies. Web servers such as Apache do not
filter returned cookies and assume that the client will only send back
cookies for requests that fall within the server-supplied subset of URLs.
However, by supplying URLs that use path traversal (/../) and character
encoding, it is possible to fool many browsers into sending a cookie to a
path outside of the originally-specified subset.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0594 to this issue. 

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.4.2 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-02"/>
        <updated date="2004-04-02"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564">CVE-2003-0564</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594">CVE-2003-0594</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191">CVE-2004-0191</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20040110001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110002" comment="mozilla is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110003" comment="mozilla is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110004" comment="mozilla-chat is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110005" comment="mozilla-chat is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110006" comment="mozilla-dom-inspector is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110007" comment="mozilla-dom-inspector is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110008" comment="mozilla-js-debugger is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110009" comment="mozilla-js-debugger is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110010" comment="mozilla-mail is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110011" comment="mozilla-mail is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110012" comment="mozilla-nspr is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110013" comment="mozilla-nspr is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110014" comment="mozilla-nspr-devel is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110015" comment="mozilla-nspr-devel is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110016" comment="mozilla-nss is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110017" comment="mozilla-nss is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110018" comment="mozilla-nss-devel is earlier than 37:1.4.2-3.0.2"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040110019" comment="mozilla-nss-devel is signed with Red Hat security key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhsa:tst:20040110001" version="303" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110001"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110002" version="303" comment="mozilla is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110003" version="303" comment="mozilla is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110004" version="303" comment="mozilla-chat is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110005" version="303" comment="mozilla-chat is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110006" version="303" comment="mozilla-dom-inspector is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110007" version="303" comment="mozilla-dom-inspector is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110008" version="303" comment="mozilla-js-debugger is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110009" version="303" comment="mozilla-js-debugger is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110010" version="303" comment="mozilla-mail is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110011" version="303" comment="mozilla-mail is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110012" version="303" comment="mozilla-nspr is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110007"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110013" version="303" comment="mozilla-nspr is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110007"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110014" version="303" comment="mozilla-nspr-devel is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110008"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110015" version="303" comment="mozilla-nspr-devel is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110008"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110016" version="303" comment="mozilla-nss is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110009"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110017" version="303" comment="mozilla-nss is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110009"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110018" version="303" comment="mozilla-nss-devel is earlier than 37:1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110010"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040110019" version="303" comment="mozilla-nss-devel is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040110010"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040110003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhsa:obj:20040110001" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110002" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110003" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-chat</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110004" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-dom-inspector</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110005" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-js-debugger</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110006" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-mail</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110007" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-nspr</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110008" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-nspr-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110009" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-nss</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040110010" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>mozilla-nss-devel</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhsa:ste:20040110001" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040110002" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">37:1.4.2-3.0.2</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040110003" version="303" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>