<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:18:02</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20040160" version="302" class="patch">
      <metadata>
        <title>RHSA-2004:160: openoffice.org security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2004:160-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-160.html"/>
	<description>OpenOffice.org is an Open Source, community-developed, multi-platform
office productivity suite.  OpenOffice internally uses inbuilt code
from neon, an HTTP and WebDAV client library.

Versions of the neon client library up to and including 0.24.4 have been
found to contain a number of format string bugs.  An attacker could create
a malicious WebDAV server in such a way as to allow arbitrary code
execution on the client should a user connect to it using OpenOffice.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-0179 to this issue.

Users of OpenOffice are advised to upgrade to these updated packages, which
contain a patch correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-04-14"/>
        <updated date="2004-04-14"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0179">CVE-2004-0179</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20040160001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160002" comment="openoffice.org is earlier than 0:1.1.0-15.EL"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160003" comment="openoffice.org is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160004" comment="openoffice.org-i18n is earlier than 0:1.1.0-15.EL"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160005" comment="openoffice.org-i18n is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160006" comment="openoffice.org-libs is earlier than 0:1.1.0-15.EL"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040160007" comment="openoffice.org-libs is signed with Red Hat security key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhsa:tst:20040160001" version="302" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160001"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160002" version="302" comment="openoffice.org is earlier than 0:1.1.0-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160003" version="302" comment="openoffice.org is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160004" version="302" comment="openoffice.org-i18n is earlier than 0:1.1.0-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160005" version="302" comment="openoffice.org-i18n is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160006" version="302" comment="openoffice.org-libs is earlier than 0:1.1.0-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040160007" version="302" comment="openoffice.org-libs is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040160004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040160003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhsa:obj:20040160001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040160002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>openoffice.org</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040160003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>openoffice.org-i18n</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040160004" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>openoffice.org-libs</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhsa:ste:20040160001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040160002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">0:1.1.0-15.EL</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040160003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>