<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:18:12</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20040414" version="302" class="patch">
      <metadata>
        <title>RHSA-2004:414: qt security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2004:414-02" ref_url="https://rhn.redhat.com/errata/RHSA-2004-414.html"/>
	<description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3.   An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2004 Red Hat, Inc.</rights>
        <issued date="2004-08-20"/>
        <updated date="2004-08-20"/>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0691">CVE-2004-0691</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0692">CVE-2004-0692</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0693">CVE-2004-0693</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20040414001" comment="Red Hat Enterprise Linux 3 is installed"/>
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414002" comment="qt is earlier than 1:3.1.2-13.4"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414003" comment="qt is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414004" comment="qt-MySQL is earlier than 1:3.1.2-13.4"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414005" comment="qt-MySQL is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414006" comment="qt-config is earlier than 1:3.1.2-13.4"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414007" comment="qt-config is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414008" comment="qt-designer is earlier than 1:3.1.2-13.4"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414009" comment="qt-designer is signed with Red Hat security key"/>
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414010" comment="qt-devel is earlier than 1:3.1.2-13.4"/>
            <criterion test_ref="oval:com.redhat.rhsa:tst:20040414011" comment="qt-devel is signed with Red Hat security key"/>
            </criteria>
    </criteria>
  </criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_test id="oval:com.redhat.rhsa:tst:20040414001" version="302" comment="redhat-release is version 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414001"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414001"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414002" version="302" comment="qt is earlier than 1:3.1.2-13.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414003" version="302" comment="qt is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414002"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414004" version="302" comment="qt-MySQL is earlier than 1:3.1.2-13.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414005" version="302" comment="qt-MySQL is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414003"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414006" version="302" comment="qt-config is earlier than 1:3.1.2-13.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414007" version="302" comment="qt-config is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414004"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414008" version="302" comment="qt-designer is earlier than 1:3.1.2-13.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414009" version="302" comment="qt-designer is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414005"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414003"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414010" version="302" comment="qt-devel is earlier than 1:3.1.2-13.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414002"/>
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20040414011" version="302" comment="qt-devel is signed with Red Hat security key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.redhat.rhsa:obj:20040414006"/>
<state state_ref="oval:com.redhat.rhsa:ste:20040414003"/>
</rpminfo_test>

  </tests>
  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ --><rpminfo_object id="oval:com.redhat.rhsa:obj:20040414001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040414002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>qt</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040414003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>qt-MySQL</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040414004" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>qt-config</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040414005" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>qt-designer</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20040414006" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>qt-devel</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ --><rpminfo_state id="oval:com.redhat.rhsa:ste:20040414001" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040414002" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">1:3.1.2-13.4</evr>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20040414003" version="302" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>

  </states>
</oval_definitions>