<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:23:41
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhba:def:20050447" version="302" class="patch">
      <metadata>
        <title>RHBA-2005:447: Updated cdrtools packages
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2005:447-02" ref_url="https://rhn.redhat.com/errata/RHBA-2005-447.html" />
	<description>Cdrecord is an application for recording audio and data CDs. Cdrecord
works with many different brands of CD recorders, fully supports
multi-sessions, and provides human-readable error messages.

The cdrecord package on Red Hat Enterprise Linux does not require setuid
root for use by normal users.  The permissions of the writer device are
changed by pam_console_apply at console login.  Setting the uid of cdrecord
to root opens a vulnerability to possible exploitation.

All users of cdrecord that setuid root should upgrade to these updated
packages, which resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0806">CVE-2004-0806</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447002" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447003" comment="cdrtools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447004" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447005" comment="cdrecord is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447006" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447007" comment="cdrecord-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447008" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447009" comment="mkisofs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhba:def:20050675" version="302" class="patch">
      <metadata>
        <title>RHBA-2005:675: gdb bug fix update
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2005:675-02" ref_url="https://rhn.redhat.com/errata/RHBA-2005-675.html" />
	<description>GDB, the GNU debugger, allows debugging of programs written in C, C++,
and other languages, by executing them in a controlled fashion, and then
printing their data.

This updated package addresses the following issues:

- GDB on ia64 had previously implemented a bug fix to work-around a kernel
problem when creating a core file via gcore.  The bug fix caused a
significant slow-down of gcore.

- GDB on Itanium issued an extraneous warning when gcore was used.

- GDB on Itanium could not successfully do an info frame for a signal
trampoline.

- GDB on AMD64 and Intel EM64T had problems attaching to a 32-bit process.

- GDB on AMD64 and Intel EM64T was not properly handling threaded watchpoints.

- GDB could not build with gcc4 when -Werror flag was set.

- GDB had problems printing inherited members of C++ classes.

- A few updates from mainline sources concerning Dwarf2 partial die in
cache support, follow-fork support, interrupted syscall support, and
DW_OP_piece read support.

All users of gdb should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1704">CVE-2005-1704</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1705">CVE-2005-1705</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhba:tst:20050675002" comment="gdb is earlier than 0:6.3.0.0-1.62" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050675003" comment="gdb is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050009" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:009: kdelibs, kdebase security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:009-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-009.html" />
	<description>The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.

Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1158
to this issue.

A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-0078 to this issue.

All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1158">CVE-2004-1158</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165">CVE-2004-1165</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0078">CVE-2005-0078</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009002" comment="kdebase is earlier than 6:3.1.3-5.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdebase is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009004" comment="kdelibs is earlier than 6:3.1.3-6.9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009006" comment="kdebase-devel is earlier than 6:3.1.3-5.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009007" comment="kdebase-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009008" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050010" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:010: vim security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:010-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-010.html" />
	<description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  It is possible
that a malicious user could create a file containing a specially crafted
modeline which could cause arbitrary command execution when viewed by a
victim.  Please note that this issue only affects users who have modelines
and filetype plugins enabled, which is not the default.  The  Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1138
to this issue.

All users of VIM are advised to upgrade to these erratum packages,
which contain a backported patch for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-05" />
        <updated date="2005-01-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138">CVE-2004-1138</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010002" comment="vim is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010004" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-X11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010006" comment="vim-common is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010010" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-minimal is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050011" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:011: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:011-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-011.html" />
	<description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-02" />
        <updated date="2005-02-02" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139">CVE-2004-1139</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1140">CVE-2004-1140</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141">CVE-2004-1141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142">CVE-2004-1142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0006">CVE-2005-0006</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007">CVE-2005-0007</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0008">CVE-2005-0008</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0009">CVE-2005-0009</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010">CVE-2005-0010</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084">CVE-2005-0084</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011002" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050012" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:012: krb5 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:012-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-012.html" />
	<description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

Additionally a temporary file bug was found in the Kerberos krb5-send-pr
program.  It is possible that an attacker could create a temporary file
that would allow an arbitrary file to be overwritten which the victim has
write access to.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0971 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-19" />
        <updated date="2005-01-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0971">CVE-2004-0971</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1189">CVE-2004-1189</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012002" comment="krb5 is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012004" comment="krb5-devel is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012006" comment="krb5-libs is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012008" comment="krb5-server is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012010" comment="krb5-workstation is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050013" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:013: cups security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:013-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-013.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package.  An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.

A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.

The lppasswd utility ignores write errors when modifying the CUPS passwd
file.  A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.

In addition to these security issues, two other problems not relating
to security have been fixed:

Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop.  This has been fixed in later
versions of CUPS, and has been backported in these updated packages.

The cancel-cups(1) man page is a symbolic link to another man page.  The
target of this link has been corrected.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1267">CVE-2004-1267</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1268">CVE-2004-1268</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269">CVE-2004-1269</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1270">CVE-2004-1270</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013002" comment="cups is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013004" comment="cups-devel is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013006" comment="cups-libs is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050018" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:018: xpdf security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:018-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-018.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf packages should upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018002" comment="xpdf is earlier than 1:2.02-9.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050019" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:019: libtiff security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:019-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-019.html" />
	<description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

iDEFENSE has reported an integer overflow bug that affects libtiff. An
attacker who has the ability to trick a user into opening a malicious TIFF
file could cause the application linked to libtiff to crash or possibly
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin reported another integer overflow in the tiffdump 
utility.  An atacker who has the ability to trick a user into opening a
malicious TIFF file with tiffdump could possibly execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308">CVE-2004-1308</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183">CVE-2004-1183</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019002" comment="libtiff is earlier than 0:3.5.7-22.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019004" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050021" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:021: kdegraphics security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:021-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-021.html" />
	<description>The kdegraphics package contains graphics applications for the K Desktop
Environment.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. The kfax application contains a copy of
the libtiff code used for parsing TIFF files and is therefore affected by
these bugs. An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause kfax to crash or possibly execute arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found. The kfax application contains a copy of the libtiff code used
for parsing TIFF files and is therefore affected by these bugs. An attacker
who has the ability to trick a user into opening a malicious TIFF file
could cause kfax to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0803 to this issue.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-14" />
        <updated date="2005-04-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803">CVE-2004-0803</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886">CVE-2004-0886</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804">CVE-2004-0804</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021002" comment="kdegraphics is earlier than 7:3.1.3-3.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021004" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050025" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:025: exim security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:025-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-025.html" />
	<description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. 

A buffer overflow was discovered in the spa_base64_to_bits function in
Exim, as originally obtained from Samba code.  If SPA authentication is
enabled, a remote attacker may be able to exploit this vulnerability to
execute arbitrary code as the 'exim' user.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to
this issue.  Please note that SPA authentication is not enabled by default
in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and
dns_build_reverse functions in Exim.  A local user can trigger these flaws
by executing exim with carefully crafted command line arguments and may be
able to gain the privileges of the 'exim' account.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0021">CVE-2005-0021</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0022">CVE-2005-0022</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025002" comment="exim is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025004" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025006" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-mon is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050026" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:026: tetex security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:026-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-026.html" />
	<description>The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026002" comment="tetex is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026004" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-afm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026006" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026008" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026010" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026012" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-latex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026014" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-xdvi is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050032" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:032: php security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:032-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-032.html" />
	<description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP. PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow. An attacker could create a carefully crafted image file in such
a way which, if parsed by a PHP script using the exif extension, could
cause a crash or potentially execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions. These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1018">CVE-2004-1018</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1019">CVE-2004-1019</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1065">CVE-2004-1065</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032002" comment="php is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032004" comment="php-devel is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032006" comment="php-domxml is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-domxml is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032008" comment="php-gd is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-gd is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032010" comment="php-imap is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-imap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032012" comment="php-ldap is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-ldap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032014" comment="php-mbstring is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-mbstring is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032016" comment="php-mysql is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032018" comment="php-ncurses is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-ncurses is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032020" comment="php-odbc is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-odbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032022" comment="php-pear is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-pear is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032024" comment="php-pgsql is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-pgsql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032026" comment="php-snmp is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-snmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032028" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-xmlrpc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050033" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:033: alsa-lib security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:033-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-033.html" />
	<description>The alsa-lib package provides a library of functions for communication with
kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack
execution protection to be disabled for the libasound.so library.  
The effect of this flaw is that stack execution protection, through NX or
Exec-Shield, would be disabled for any application linked to libasound. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a
patched version of the library which correctly enables stack execution
protection.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0087">CVE-2005-0087</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033002" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033003" comment="alsa-lib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033004" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033005" comment="alsa-lib-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050034" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:034: xpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:034-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-034.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf. An attacker could construct a carefully crafted PDF file that could
cause Xpdf to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org).  Red Hat Enterprise Linux 4 contained a fix for this
issue, but it was found to be incomplete and left 64-bit architectures
vulnerable.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0206 to this issue.

All users of Xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050034002" comment="xpdf is earlier than 1:3.00-11.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050035" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:035: libtiff security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:035-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-035.html" />
	<description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

infamous41md discovered integer overflow flaws in libtiff.  An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to overflow a heap buffer when the
file was opened by a victim.  Due to the nature of the overflow it is
unlikely that it is possible to use this flaw to execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin discovered an integer overflow flaw in libtiff.  An
attacker could create a carefully crafted TIFF file in such a way that it
could cause an application linked with libtiff to crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308">CVE-2004-1308</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183">CVE-2004-1183</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050035002" comment="libtiff is earlier than 0:3.6.1-8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050035004" comment="libtiff-devel is earlier than 0:3.6.1-8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050036" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:036: vim security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:036-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-036.html" />
	<description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  An attacker
could create a text file containing a specially crafted modeline which
could cause arbitrary command execution when viewed by a victim using VIM. 
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-1138 to this issue.  Please note that this issue only affects
users who have modelines and filetype plugins enabled, which is not the
default.  

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM.  A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue. 

All users of VIM are advised to upgrade to these erratum packages,
which contain backported patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138">CVE-2004-1138</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0069">CVE-2005-0069</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036002" comment="vim is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036004" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-X11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036006" comment="vim-common is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036008" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036010" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-minimal is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050037" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:037: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:037-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-037.html" />
	<description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization.  (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084) 

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139">CVE-2004-1139</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1140">CVE-2004-1140</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141">CVE-2004-1141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142">CVE-2004-1142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0006">CVE-2005-0006</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007">CVE-2005-0007</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0008">CVE-2005-0008</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0009">CVE-2005-0009</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010">CVE-2005-0010</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084">CVE-2005-0084</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050037002" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050037004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050038" version="304" class="patch">
      <metadata>
        <title>RHSA-2005:038: mozilla security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:038-04" ref_url="https://rhn.redhat.com/errata/RHSA-2005-038.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way
Mozilla handles NNTP URLs.  If a user visits a malicious web page or is
convinced to click on a malicious link, it may be possible for an attacker
to execute arbitrary code on the victim's machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316">CVE-2004-1316</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038002" comment="mozilla is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038004" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038006" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038008" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038010" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038012" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038014" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038016" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038018" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038020" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050039" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:039: enscript security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:039-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-039.html" />
	<description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences. A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document. An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments. These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184">CVE-2004-1184</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185">CVE-2004-1185</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186">CVE-2004-1186</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039002" comment="enscript is earlier than 0:1.6.1-24.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050040" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:040: enscript security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:040-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-040.html" />
	<description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences.  A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document.  An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments.  These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184">CVE-2004-1184</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185">CVE-2004-1185</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186">CVE-2004-1186</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050040002" comment="enscript is earlier than 0:1.6.1-28.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050043" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:043: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:043-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-043.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1235 to
this issue.

A flaw was discovered where an executable could cause a VMA overlap leading
to a crash.  A local user could trigger this flaw by creating a carefully
crafted a.out binary on 32-bit systems or a carefully crafted ELF binary
on Itanium systems.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0003 to this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0001 to this issue. A patch
that coincidentally fixed this issue was committed to the Update 4 kernel
release in December 2004.  Therefore Red Hat Enterprise Linux 3 kernels
provided by RHBA-2004:550 and subsequent updates are not vulnerable to
this issue.

A flaw in the system call filtering code in the audit subsystem included
in Red Hat Enterprise Linux 3 allowed a local user to cause a crash when
auditing was enabled.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1237 to this issue.

Olaf Kirch discovered that the recent security fixes for cmsg_len handling
(CAN-2004-1016) broke 32-bit compatibility on 64-bit platforms such as
AMD64 and Intel EM64T. A patch to correct this issue is included.

A recent Internet Draft by Fernando Gont recommended that ICMP Source
Quench messages be ignored by hosts.  A patch to ignore these messages is
included.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-18" />
        <updated date="2005-01-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791">CVE-2004-0791</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1074">CVE-2004-1074</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235">CVE-2004-1235</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1237">CVE-2004-1237</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0003">CVE-2005-0003</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043002" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043004" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-smp-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043010" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-BOOT is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043012" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043014" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-source is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043016" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050045" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:045: krb5 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:045-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-045.html" />
	<description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1189">CVE-2004-1189</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045002" comment="krb5 is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045004" comment="krb5-devel is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045006" comment="krb5-libs is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045008" comment="krb5-server is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045010" comment="krb5-workstation is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050049" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:049: cups security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:049-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-049.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit these buffer overflow
vulnerabilities on x86 architectures.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049002" comment="cups is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049004" comment="cups-devel is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049006" comment="cups-libs is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050053" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:053: CUPS security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:053-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-053.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects CUPS due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause CUPS to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects the CUPS pdftops filter due to a shared codebase.  An attacker
who has the ability to send a malicious PDF file to a printer could
possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the ParseCommand function in the
hpgltops program. An attacker who has the ability to send a malicious HPGL
file to a printer could possibly execute arbitrary code as the "lp" user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1267 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

The lppasswd utility was found to ignore write errors when modifying the
CUPS passwd file. A local user who is able to fill the associated file
system could corrupt the CUPS password file or prevent future uses of
lppasswd. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility was found to not verify that the passwd.new file is
different from STDERR, which could allow local users to control output to
passwd.new via certain user input that triggers an error message. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1270 to this issue.

All users of cups should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1267">CVE-2004-1267</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1268">CVE-2004-1268</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269">CVE-2004-1269</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1270">CVE-2004-1270</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053002" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050057" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:057: gpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:057-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-057.html" />
	<description>GPdf is a viewer for Portable Document Format (PDF) files for GNOME. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

Users should update to this erratum package which contains backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050057002" comment="gpdf is earlier than 0:2.8.2-4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050059" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:059: xpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:059-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-059.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found when processing the /Encrypt /Length tag.
An attacker could construct a carefully crafted PDF file that could cause
Xpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf package should upgrade to this updated package,
which resolves this issue</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050059002" comment="xpdf is earlier than 1:2.02-9.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050060" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:060: squid security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:060-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-060.html" />
	<description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious webpage
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious Web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious Web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094">CVE-2005-0094</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0095">CVE-2005-0095</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0096">CVE-2005-0096</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097">CVE-2005-0097</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0173">CVE-2005-0173</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0174">CVE-2005-0174</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175">CVE-2005-0175</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211">CVE-2005-0211</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241">CVE-2005-0241</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050061" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:061: squid security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-061.html" />
	<description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious web page
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-11" />
        <updated date="2005-02-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094">CVE-2005-0094</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0095">CVE-2005-0095</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0096">CVE-2005-0096</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097">CVE-2005-0097</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0173">CVE-2005-0173</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0174">CVE-2005-0174</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175">CVE-2005-0175</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211">CVE-2005-0211</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241">CVE-2005-0241</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050061002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050065" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:065: kdelibs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:065-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-065.html" />
	<description>The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in
the Konqueror web browser. If a user has Java enabled in Konqueror and
visits a malicious website, the website could run a carefully crafted
Java-applet and obtain escalated privileges allowing reading and writing of
arbitrary files with the privileges of the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave.  KDE applications such as
Konqueror could be forced to execute arbitrary FTP commands via a carefully
crafted ftp URL.  The URL could also be crafted in such a way as to send an
arbitrary email via SMTP.  An attacker could make use of this flaw if a
victim visits a malicious web site. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1145">CVE-2004-1145</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165">CVE-2004-1165</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050065002" comment="kdelibs is earlier than 6:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050065004" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050066" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:066: kdegraphics security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:066-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-066.html" />
	<description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that
also affects kpdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects kpdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf which also affects
kpdf due to a shared codebase. An attacker could construct a carefully
crafted PDF file that could cause kpdf to crash or possibly execute
arbitrary code when opened. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888">CVE-2004-0888</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050066002" comment="kdegraphics is earlier than 7:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050066004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050068" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:068: less security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:068-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-068.html" />
	<description>The less utility is a text file browser that resembles more, but has
extended capabilities.

Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue.  Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit this vulnerability on x86
architectures.

All users of the less package should upgrade to this updated package,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0086">CVE-2005-0086</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050068002" comment="less is earlier than 0:378-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050068003" comment="less is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050069" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:069: perl security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:069-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-069.html" />
	<description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0077">CVE-2005-0077</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050069002" comment="perl-DBI is earlier than 0:1.32-9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050070" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:070: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:070-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-070.html" />
	<description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible
that a TIFF image file with an invalid tag could cause ImageMagick to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a
specially crafted TIFF image file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible
that a specially crafted PSD file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser.  It is possible
that an attacker could execute arbitrary code by tricking a user into
opening a specially crafted SGI image file. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005">CVE-2005-0005</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0397">CVE-2005-0397</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0759">CVE-2005-0759</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0760">CVE-2005-0760</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0761">CVE-2005-0761</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0762">CVE-2005-0762</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070002" comment="ImageMagick is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070004" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070006" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070008" comment="ImageMagick-devel is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070010" comment="ImageMagick-perl is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050071" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:071: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:071-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-071.html" />
	<description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005">CVE-2005-0005</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071002" comment="ImageMagick is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050072" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:072: perl-DBI security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:072-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-072.html" />
	<description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0077">CVE-2005-0077</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050072002" comment="perl-DBI is earlier than 0:1.40-8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050073" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:073: cpio security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:073-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-073.html" />
	<description>GNU cpio copies files into or out of a cpio or tar archive.  

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option.  This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

Users of cpio should upgrade to this updated package, which resolves
this issue.

Red Hat would like to thank Mike O'Connor for bringing this issue to our
attention.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1572">CVE-1999-1572</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050073002" comment="cpio is earlier than 0:2.5-7.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050074" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:074: rsh security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:074-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-074.html" />
	<description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory.  This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rexec command failed with "Invalid Argument", because the code
used sigaction() as an unsupported signal.

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

The rexec command prompted for username and password regardless of the
~/.netrc configuration file contents. This updated package contains a patch
that no longer skips the ~/.netrc file. 

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0175">CVE-2004-0175</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074002" comment="rsh is earlier than 0:0.17-17.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074004" comment="rsh-server is earlier than 0:0.17-17.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050080" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:080: cpio security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:080-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-080.html" />
	<description>GNU cpio copies files into or out of a cpio or tar archive. 

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option. This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

All users of cpio should upgrade to this updated package, which resolves
this issue, and adds support for large files (> 2GB).</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1572">CVE-1999-1572</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050080002" comment="cpio is earlier than 0:2.5-3e.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050081" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:081: ghostscript security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:081-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-081.html" />
	<description>Ghostscript is a program for displaying PostScript files or printing them
to non-PostScript printers.

A bug was found in the way several of Ghostscript's utility scripts created
temporary files. A local user could cause these utilities to overwrite
files that the victim running the utility has write access to.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2004-0967 to
this issue.

Additionally, this update addresses the following issue:

A problem has been identified in the PDF output driver, which can cause
output to be delayed indefinitely on some systems.  The fix has been
backported from GhostScript 7.07.

All users of ghostscript should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0967">CVE-2004-0967</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081002" comment="ghostscript is earlier than 0:7.05-32.1.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081003" comment="ghostscript is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081004" comment="ghostscript-devel is earlier than 0:7.05-32.1.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081005" comment="ghostscript-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081006" comment="hpijs is earlier than 0:1.3-32.1.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050081007" comment="hpijs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050090" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:090: htdig security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:090-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-090.html" />
	<description>The ht://Dig system is a Web search and indexing system for a small domain
or intranet.

Michael Krax reported a cross-site scripting bug affecting htdig. An
attacker could construct a carefully crafted URL which can cause a web
browser to execute malicious script once visited.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-0085
to this issue.

Users of htdig should upgrade to these updated packages, which contain a
backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0085">CVE-2005-0085</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050090002" comment="htdig is earlier than 3:3.2.0b6-3.40.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050090003" comment="htdig is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050090004" comment="htdig-web is earlier than 3:3.2.0b6-3.40.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050090005" comment="htdig-web is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050092" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:092: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:092-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-092.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered multiple vulnerabilities in the IGMP
functionality.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  (CAN-2005-0001)

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  (CAN-2004-1235)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architecture was discovered.  A local user could use this flaw to write to
privileged IO ports.  (CAN-2005-0204)

The Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not
properly check the DMA lock, which could allow remote attackers or local
users to cause a denial of service (X Server crash) or possibly modify the
video output. (CAN-2004-1056)

OGAWA Hirofumi discovered incorrect tables sizes being used in the
filesystem Native Language Support ASCII translation table.  This could
lead to a denial of service (system crash).  (CAN-2005-0177)

Michael Kerrisk discovered a flaw in the 2.6.9 kernel which allows users to
unlock arbitrary shared memory segments.  This flaw could lead to
applications not behaving as expected.  (CAN-2005-0176)

Improvements in the POSIX signal and tty standards compliance exposed
a race condition.  This flaw can be triggered accidentally by threaded
applications or deliberately by a malicious user and can result in a
denial of service (crash) or in occasional cases give access to a small
random chunk of kernel memory.  (CAN-2005-0178)

The PaX team discovered a flaw in mlockall introduced in the 2.6.9 kernel.
An unprivileged user could use this flaw to cause a denial of service
(CPU and memory consumption or crash).  (CAN-2005-0179)

Brad Spengler discovered multiple flaws in sg_scsi_ioctl in the 2.6 kernel.
An unprivileged user may be able to use this flaw to cause a denial of
service (crash) or possibly other actions.  (CAN-2005-0180)

Kirill Korotaev discovered a missing access check regression in the Red Hat
Enterprise Linux 4 kernel 4GB/4GB split patch.  On systems using the
hugemem kernel, a local unprivileged user could use this flaw to cause a
denial of service (crash).  (CAN-2005-0090)

A flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch can
allow syscalls to read and write arbitrary kernel memory.  On systems using
the hugemem kernel, a local unprivileged user could use this flaw to gain
privileges.  (CAN-2005-0091)

An additional flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split
patch was discovered. On x86 systems using the hugemem kernel, a local
unprivileged user may be able to use this flaw to cause a denial of service
(crash).  (CAN-2005-0092)

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1056">CVE-2004-1056</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1137">CVE-2004-1137</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235">CVE-2004-1235</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0001">CVE-2005-0001</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0090">CVE-2005-0090</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0091">CVE-2005-0091</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0092">CVE-2005-0092</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0176">CVE-2005-0176</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0177">CVE-2005-0177</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0178">CVE-2005-0178</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0179">CVE-2005-0179</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0180">CVE-2005-0180</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0204">CVE-2005-0204</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092002" comment="kernel is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092004" comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092006" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092008" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092009" comment="kernel-hugemem-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092010" comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092012" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092013" comment="kernel-smp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092014" comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050094" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:094: thunderbird security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:094-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-094.html" />
	<description>Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victim's
clipboard. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0146 to this issue.

A bug was found in the way Thunderbird handled cookies when loading content
over HTTP regardless of the user's preference. It is possible that a
particular user could be tracked through the use of malicious mail messages
which load content over HTTP. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0149 to this issue.

Users of Thunderbird are advised to upgrade to this updated package,
which contains Thunderbird version 1.0 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-05-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0146">CVE-2005-0146</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149">CVE-2005-0149</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050094002" comment="thunderbird is earlier than 0:1.0-1.1.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050099" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:099: squirrelmail security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:099-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-099.html" />
	<description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0075">CVE-2005-0075</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0103">CVE-2005-0103</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0104">CVE-2005-0104</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050099002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050100" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:100: mod_python security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:100-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-100.html" />
	<description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0088">CVE-2005-0088</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050100002" comment="mod_python is earlier than 0:3.1.3-5.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050100003" comment="mod_python is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050102" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:102: dbus security update.
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:102-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-102.html" />
	<description>D-BUS is a system for sending messages between applications. It is
used both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Dan Reed discovered that a user can send and listen to messages on another
user's per-user session bus if they know the address of the socket. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0201 to this issue.  In Red Hat Enterprise Linux 4, the
per-user session bus is only used for printing notifications,  therefore
this issue would only allow a local user to examine or send additional
print notification messages.

Users of dbus are advised to upgrade to these updated packages,
which contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0201">CVE-2005-0201</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102002" comment="dbus is earlier than 0:0.22-12.EL.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102003" comment="dbus is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102004" comment="dbus-devel is earlier than 0:0.22-12.EL.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102005" comment="dbus-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102006" comment="dbus-glib is earlier than 0:0.22-12.EL.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102007" comment="dbus-glib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102008" comment="dbus-python is earlier than 0:0.22-12.EL.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102009" comment="dbus-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102010" comment="dbus-x11 is earlier than 0:0.22-12.EL.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050102011" comment="dbus-x11 is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050103" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:103: perl security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:103-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-103.html" />
	<description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

An unsafe file permission bug was discovered in the rmtree() function in
the File::Path module.  The rmtree() function removes files and directories
in an insecure manner, which could allow a local user to read or delete
arbitrary files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0452 to this issue.

Users of Perl are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452">CVE-2004-0452</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0155">CVE-2005-0155</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0156">CVE-2005-0156</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103002" comment="perl is earlier than 3:5.8.5-12.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103004" comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050104" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:104: mod_python security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:104-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-104.html" />
	<description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0088">CVE-2005-0088</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050104002" comment="mod_python is earlier than 0:3.0.3-5.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050100003" comment="mod_python is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050105" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:105: perl security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:105-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-105.html" />
	<description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-07" />
        <updated date="2005-02-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452">CVE-2004-0452</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0155">CVE-2005-0155</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0156">CVE-2005-0156</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105002" comment="perl is earlier than 2:5.8.0-89.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105004" comment="perl-CGI is earlier than 2:2.81-89.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CGI is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105006" comment="perl-CPAN is earlier than 2:1.61-89.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CPAN is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105008" comment="perl-DB_File is earlier than 2:1.804-89.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050105010" comment="perl-suidperl is earlier than 2:5.8.0-89.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050106" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:106: openssh security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:106-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-106.html" />
	<description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH
replaces rlogin and rsh, and provides secure encrypted communications
between two untrusted hosts over an insecure network. X11 connections and
arbitrary TCP/IP ports can also be forwarded over a secure channel. Public
key authentication can be used for "passwordless" access to servers.

The scp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses scp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also correct the following bugs:

On systems where direct ssh access for the root user was disabled by
configuration (setting "PermitRootLogin no"), attempts to guess the root
password could be judged as sucessful or unsucessful by observing a delay.

On systems where the privilege separation feature was turned on, the user
resource limits were not correctly set if the configuration specified to
raise them above the defaults.  It was also not possible to change an
expired password.

Users of openssh should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0175">CVE-2004-0175</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106002" comment="openssh is earlier than 0:3.6.1p2-33.30.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106004" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-askpass is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106006" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-askpass-gnome is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106008" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-clients is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106010" comment="openssh-server is earlier than 0:3.6.1p2-33.30.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050108" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:108: python security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:108-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-108.html" />
	<description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0089">CVE-2005-0089</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108002" comment="python is earlier than 0:2.3.4-14.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108004" comment="python-devel is earlier than 0:2.3.4-14.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108006" comment="python-docs is earlier than 0:2.3.4-14.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-docs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108008" comment="python-tools is earlier than 0:2.3.4-14.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108010" comment="tkinter is earlier than 0:2.3.4-14.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050109" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:109: python security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:109-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-109.html" />
	<description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0089">CVE-2005-0089</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050109002" comment="python is earlier than 0:2.2.3-6.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050109004" comment="python-devel is earlier than 0:2.2.3-6.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050109006" comment="python-tools is earlier than 0:2.2.3-6.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050109008" comment="tkinter is earlier than 0:2.2.3-6.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050110" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:110: emacs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:110-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-110.html" />
	<description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running emacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100">CVE-2005-0100</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110002" comment="emacs is earlier than 0:21.3-19.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110004" comment="emacs-common is earlier than 0:21.3-19.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110005" comment="emacs-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110006" comment="emacs-el is earlier than 0:21.3-19.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110007" comment="emacs-el is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110008" comment="emacs-leim is earlier than 0:21.3-19.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-leim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110010" comment="emacs-nox is earlier than 0:21.3-19.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-nox is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050112" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:112: emacs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:112-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-112.html" />
	<description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running emacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100">CVE-2005-0100</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050112002" comment="emacs is earlier than 0:21.3-4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050112004" comment="emacs-el is earlier than 0:21.3-4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110007" comment="emacs-el is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050112006" comment="emacs-leim is earlier than 0:21.3-4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-leim is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050122" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:122: vim security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:122-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-122.html" />
	<description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM. A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue.

All users of VIM are advised to upgrade to these erratum packages, which
contain a backported patche for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0069">CVE-2005-0069</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050122002" comment="vim is earlier than 1:6.3.046-0.30E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050122004" comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-X11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050122006" comment="vim-common is earlier than 1:6.3.046-0.30E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050122008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050122010" comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-minimal is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050128" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:128: imap security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:128-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-128.html" />
	<description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access
protocols.

A logic error in the CRAM-MD5 code in the University of Washington IMAP
(UW-IMAP) server was discovered.  When Challenge-Response Authentication
Mechanism with MD5 (CRAM-MD5) is enabled, UW-IMAP does not properly enforce
all the required conditions for successful authentication, which could
allow remote attackers to authenticate as arbitrary users.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
 CAN-2005-0198 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-23" />
        <updated date="2005-02-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0198">CVE-2005-0198</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128002" comment="imap is earlier than 1:2002d-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128004" comment="imap-devel is earlier than 1:2002d-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128006" comment="imap-utils is earlier than 1:2002d-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050132" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:132: cups security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:132-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-132.html" />
	<description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect Xpdf.  CUPS contained a copy of the Xpdf code
used for parsing PDF files and was therefore affected by these bugs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2004-0888 to this issue, and Red Hat released erratum
RHSA-2004:543 with updated packages.

It was found that the patch used to correct this issue was not sufficient
and did not fully protect CUPS running on 64-bit architectures.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue. 

These updated packages also include a fix that prevents the CUPS
initscript from being accidentally replaced.

All users of CUPS on 64-bit architectures should upgrade to these updated
packages, which contain a corrected patch and are not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050132002" comment="cups is earlier than 1:1.1.17-13.3.27" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050132004" comment="cups-devel is earlier than 1:1.1.17-13.3.27" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050132006" comment="cups-libs is earlier than 1:1.1.17-13.3.27" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050133" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:133: xemacs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:133-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-133.html" />
	<description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running xemacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100">CVE-2005-0100</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133002" comment="xemacs is earlier than 0:21.4.15-10.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133004" comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133005" comment="xemacs-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133006" comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133007" comment="xemacs-el is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133008" comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-info is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133010" comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-nox is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050134" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:134: xemacs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:134-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-134.html" />
	<description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running xemacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0100">CVE-2005-0100</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050134002" comment="xemacs is earlier than 0:21.4.13-8.ent.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050134004" comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133007" comment="xemacs-el is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050134006" comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-info is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050135" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:135: squirrelmail security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:135-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-135.html" />
	<description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0075">CVE-2005-0075</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0103">CVE-2005-0103</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0104">CVE-2005-0104</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050135002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050136" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:136: mailman security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:136-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-136.html" />
	<description>The mailman package is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0202">CVE-2005-0202</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050136002" comment="mailman is earlier than 3:2.1.5-24.rhel3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050137" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:137: mailman security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:137-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-137.html" />
	<description>Mailman is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.  

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of Mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0202">CVE-2005-0202</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050137002" comment="mailman is earlier than 3:2.1.5-31.rhel4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050138" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:138: postgresql security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:138-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-138.html" />
	<description>A flaw in the LOAD command in PostgreSQL was discovered. A local user
could use this flaw to load arbitrary shared libraries and therefore
execute arbitrary code, gaining the privileges of the PostgreSQL server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered. A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL. A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found. A user could create carefully crafted arrays and cause a denial of
service (crash). The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

The update also fixes some minor problems, notably conflicts with SELinux.

Users of postgresql should update to these erratum packages that contain
patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0227">CVE-2005-0227</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0244">CVE-2005-0244</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0245">CVE-2005-0245</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0246">CVE-2005-0246</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247">CVE-2005-0247</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138002" comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138004" comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-contrib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138006" comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138008" comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138010" comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138012" comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138014" comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138016" comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138018" comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138020" comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-tcl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138022" comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050141" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:141: rh-postgresql security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:141-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-141.html" />
	<description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw in the LOAD command in PostgreSQL was discovered.  A local user
could use this flaw to load arbitrary shared librarys and therefore execute
arbitrary code, gaining the privileges of the PostgreSQL server.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered.  A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL.  A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found.  A user could create carefully crafted arrays and cause a denial of
service (crash).  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

Users of PostgreSQL are advised to update to these erratum packages which
are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0227">CVE-2005-0227</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0244">CVE-2005-0244</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0245">CVE-2005-0245</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0246">CVE-2005-0246</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247">CVE-2005-0247</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141002" comment="rh-postgresql is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141003" comment="rh-postgresql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141004" comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141005" comment="rh-postgresql-contrib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141006" comment="rh-postgresql-devel is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141007" comment="rh-postgresql-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141008" comment="rh-postgresql-docs is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141009" comment="rh-postgresql-docs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141010" comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141011" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141012" comment="rh-postgresql-libs is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141013" comment="rh-postgresql-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141014" comment="rh-postgresql-pl is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141015" comment="rh-postgresql-pl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141016" comment="rh-postgresql-python is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141017" comment="rh-postgresql-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141018" comment="rh-postgresql-server is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141019" comment="rh-postgresql-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141020" comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141021" comment="rh-postgresql-tcl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141022" comment="rh-postgresql-test is earlier than 0:7.3.9-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050141023" comment="rh-postgresql-test is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050152" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:152: postfix security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:152-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-152.html" />
	<description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the ipv6 patch used with Postfix.  When the file
/proc/net/if_inet6 is not available and permit_mx_backup is enabled in
smtpd_recipient_restrictions, this flaw could allow remote attackers to
bypass e-mail restrictions and perform mail relaying by sending mail to an
IPv6 hostname.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0337 to this issue.

These updated packages also fix the following problems:

- wrong permissions on doc directory
- segfault when gethostbyname or gethostbyaddr fails

All users of postfix should upgrade to these updated packages, which
contain patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0337">CVE-2005-0337</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050152002" comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050152003" comment="postfix is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050152004" comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050152005" comment="postfix-pflogsumm is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050165" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:165: rsh security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:165-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-165.html" />
	<description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0175">CVE-2004-0175</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050165002" comment="rsh is earlier than 0:0.17-25.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050165004" comment="rsh-server is earlier than 0:0.17-25.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050173" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:173: squid security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:173-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-173.html" />
	<description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles FQDN lookups.  It was possible  
to crash the Squid server by sending a carefully crafted DNS response to  
an FQDN lookup.  The Common Vulnerabilities and Exposures project  
(cve.mitre.org) has assigned the name CAN-2005-0446 to this issue.  
  
Users of squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0446">CVE-2005-0446</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050173002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050175" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:175: kdenetwork security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:175-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-175.html" />
	<description>The kdenetwork packages contain a collection of networking applications for
the K Desktop Environment.

A bug was found in the way kppp handles privileged file descriptors.  A
malicious local user could make use of this flaw to modify the /etc/hosts
or /etc/resolv.conf files, which could be used to spoof domain information. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0205 to this issue.

Please note that the default installation of kppp on Red Hat Enterprise
Linux uses consolehelper and is not vulnerable to this issue.  However, the
kppp FAQ provides instructions for removing consolehelper and running kppp
suid root, which is a vulnerable configuration.

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0205">CVE-2005-0205</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050175002" comment="kdenetwork is earlier than 7:3.1.3-1.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050175004" comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050176" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:176: firefox security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:176-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-176.html" />
	<description>Mozilla Firefox is an open source Web browser.

A bug was found in the Firefox string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

A bug was found in the way Firefox handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Firefox allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527).

A flaw was found in the way Firefox displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Firefox handles plug-in temporary files. A
malicious local user could create a symlink to a victims directory, causing
it to be deleted when the victim exits Firefox. (CAN-2005-0578)

A bug has been found in one of Firefox's UTF-8 converters. It may be
possible for an attacker to supply a specially crafted UTF-8 string to the
buggy converter, leading to arbitrary code execution. (CAN-2005-0592)

A bug was found in the Firefox javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Firefox displays the HTTP authentication prompt.
When a user is prompted for authentication, the dialog window is displayed
over the active tab, regardless of the tab that caused the pop-up to appear
and could trick a user into entering their username and password for a
trusted site.  (CAN-2005-0584)

A bug was found in the way Firefox displays the save file dialog. It is
possible for a malicious webserver to spoof the Content-Disposition header,
tricking the user into thinking they are downloading a different filetype.
(CAN-2005-0586)

A bug was found in the way Firefox handles users "down-arrow" through auto
completed choices. When an autocomplete choice is selected, the information
is copied into the input control, possibly allowing a malicious web site to
steal information by tricking a user into arrowing through autocompletion
choices. (CAN-2005-0589)

Several bugs were found in the way Firefox displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0593)

A bug was found in the way Firefox displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

A bug was found in the way Firefox handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

A bug was found in the way Firefox displays the installation confirmation
dialog. An attacker could add a long user:pass before the true hostname,
tricking a user into thinking they were installing content from a trusted
source. (CAN-2005-0590)

A bug was found in the way Firefox displays download and security dialogs.
An attacker could cover up part of a dialog window tricking the user into
clicking "Allow" or "Open", which could potentially lead to arbitrary code
execution. (CAN-2005-0591)

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-01" />
        <updated date="2005-03-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1156">CVE-2004-1156</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0231">CVE-2005-0231</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0232">CVE-2005-0232</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233">CVE-2005-0233</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255">CVE-2005-0255</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0527">CVE-2005-0527</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0578">CVE-2005-0578</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0584">CVE-2005-0584</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585">CVE-2005-0585</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0586">CVE-2005-0586</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0588">CVE-2005-0588</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0589">CVE-2005-0589</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0590">CVE-2005-0590</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0591">CVE-2005-0591</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0592">CVE-2005-0592</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593">CVE-2005-0593</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050176002" comment="firefox is earlier than 0:1.0.1-1.4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050198" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:198: xorg-x11 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:198-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-198.html" />
	<description>X.Org X11 is the X Window System which provides the core functionality
of the Linux GUI desktop.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
carefully crafted XPM file in such a way that it could cause an application
linked with libXpm to execute arbitrary code when the file was opened by a
victim. The Common Vulnerabilities and Exposures project  (cve.mitre.org)
has assigned the name CAN-2005-0605 to this issue. 

Since the initial release of Red Hat Enterprise Linux 4, a number of issues
have been addressed in the X.Org X11 X Window System.  This erratum also
updates X11R6.8 to the latest stable point release (6.8.2), which includes
various stability and reliability fixes including (but not limited to) the
following:

- The 'radeon' driver has been modified to disable "RENDER" acceleration
  by default, due to a bug in the implementation which has not yet
  been isolated.  This can be manually re-enabled by using the
  following option in the device section of the X server config file:

    Option "RenderAccel"

- The 'vmware' video driver is now available on 64-bit AMD64 and
  compatible systems.

- The Intel 'i810' video driver is now available on 64-bit EM64T
  systems.

- Stability fixes in the X Server's PCI handling layer for 64-bit systems,
  which resolve some issues reported by "vesa" and "nv" driver users.

- Support for Hewlett Packard's Itanium ZX2 chipset.

- Nvidia "nv" video driver update provides support for some of
  the newer Nvidia chipsets, as well as many stability and reliability
  fixes.

- Intel i810 video driver stability update, which fixes the widely
  reported i810/i815 screen refresh issues many have experienced.

- Packaging fixes for multilib systems, which permit both 32-bit
  and 64-bit X11 development environments to be simultaneously installed
  without file conflicts.

In addition to the above highlights, the X.Org X11 6.8.2 release has a
large number of additional stability fixes which resolve various other
issues reported since the initial release of Red Hat Enterprise Linux 4. 

All users of X11 should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0605">CVE-2005-0605</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198002" comment="fonts-xorg is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="fonts-xorg is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198004" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198006" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198008" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198010" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198012" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-Xnest is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198014" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198016" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198018" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198020" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198022" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198024" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198026" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198028" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-sdk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198030" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198032" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-twm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198034" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-xauth is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198036" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-xdm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198038" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198039" comment="xorg-x11-xfs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198040" comment="fonts-xorg-100dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198041" comment="fonts-xorg-100dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198042" comment="fonts-xorg-75dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198043" comment="fonts-xorg-75dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198044" comment="fonts-xorg-ISO8859-14-100dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198045" comment="fonts-xorg-ISO8859-14-100dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198046" comment="fonts-xorg-ISO8859-14-75dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198047" comment="fonts-xorg-ISO8859-14-75dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198048" comment="fonts-xorg-ISO8859-15-100dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198049" comment="fonts-xorg-ISO8859-15-100dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198050" comment="fonts-xorg-ISO8859-15-75dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198051" comment="fonts-xorg-ISO8859-15-75dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198052" comment="fonts-xorg-ISO8859-2-100dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198053" comment="fonts-xorg-ISO8859-2-100dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198054" comment="fonts-xorg-ISO8859-2-75dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198055" comment="fonts-xorg-ISO8859-2-75dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198056" comment="fonts-xorg-ISO8859-9-100dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198057" comment="fonts-xorg-ISO8859-9-100dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198058" comment="fonts-xorg-ISO8859-9-75dpi is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198059" comment="fonts-xorg-ISO8859-9-75dpi is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198060" comment="fonts-xorg-base is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198061" comment="fonts-xorg-base is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198062" comment="fonts-xorg-cyrillic is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198063" comment="fonts-xorg-cyrillic is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198064" comment="fonts-xorg-syriac is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198065" comment="fonts-xorg-syriac is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198066" comment="fonts-xorg-truetype is earlier than 0:6.8.1.1-1.EL.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198067" comment="fonts-xorg-truetype is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050201" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:201: squid security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:201-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-201.html" />
	<description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles fully qualified domain name (FQDN)
lookups.  A malicious DNS server could crash Squid by sending a carefully
crafted DNS response to an FQDN lookup.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0446 to
this issue.  
 
This erratum also includes two minor patches to the LDAP helpers.  One 
corrects a slight malformation in ldap search requests (although all 
known LDAP servers accept the requests).  The other adds documentation 
for the -v option to the ldap helpers. 
 
Users of Squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0446">CVE-2005-0446</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050201002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050213" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:213: xpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:213-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-213.html" />
	<description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). RHSA-2004:592 contained a fix for this issue, but it was
found to be incomplete and left 64-bit architectures vulnerable. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue.

All users of xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050213002" comment="xpdf is earlier than 1:2.02-9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050215" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:215: gaim security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:215-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-215.html" />
	<description>The Gaim application is a multi-protocol instant messaging client.

Two HTML parsing bugs were discovered in Gaim. It is possible that a remote
attacker could send a specially crafted message to a Gaim client, causing
it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0208 and CAN-2005-0473 to
these issues.

A bug in the way Gaim processes SNAC packets was discovered.  It is
possible that a remote attacker could send a specially crafted SNAC packet
to a Gaim client, causing the client to stop responding.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0472 to this issue.

Additionally, various client crashes, memory leaks, and protocol issues
have been resolved.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.1.4 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-10" />
        <updated date="2005-03-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0208">CVE-2005-0208</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0472">CVE-2005-0472</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0473">CVE-2005-0473</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215002" comment="gaim is earlier than 1:1.1.4-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215005" comment="gaim is earlier than 1:1.1.4-1.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050232" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:232: ipsec-tools security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:232-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-232.html" />
	<description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel. The ipsec-tools package includes:

- setkey, a program to directly manipulate policies and SAs
- racoon, an IKEv1 keying daemon

A bug was found in the way the racoon daemon handled incoming ISAKMP
requests.  It is possible that an attacker could crash the racoon daemon by
sending a specially crafted ISAKMP packet.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0398 to
this issue. 

Additionally, the following issues have been fixed:
- racoon mishandled restarts in the presence of stale administration sockets.
- on Red Hat Enterprise Linux 4, racoon and setkey did not properly set up
  forward policies, which prevented tunnels from working.

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0398">CVE-2005-0398</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050232002" comment="ipsec-tools is earlier than 0:0.2.5-0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050232003" comment="ipsec-tools is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050232005" comment="ipsec-tools is earlier than 0:0.3.3-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050232003" comment="ipsec-tools is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050235" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:235: mailman security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:235-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-235.html" />
	<description>Mailman manages electronic mail discussion and e-newsletter lists. 

A cross-site scripting (XSS) flaw in the driver script of mailman prior to
version 2.1.5 could allow remote attackers to execute scripts as other web
users. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1177 to this issue.

Users of mailman should update to this erratum package, which corrects this
issue by turning on STEALTH_MODE by default and using Utils.websafe() to
quote the html.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1177">CVE-2004-1177</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050235002" comment="mailman is earlier than 3:2.1.5-25.rhel3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050235005" comment="mailman is earlier than 3:2.1.5-33.rhel4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050238" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:238: evolution security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:238-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-238.html" />
	<description>Evolution is the GNOME collection of personal information management (PIM)
tools. Evolution includes a mailer, calendar, contact manager, and
communication facility.  The tools which make up Evolution are tightly
integrated with one another and act as a seamless personal information
management tool.

A bug was found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default. Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

Additionally, these updated packages address the following issues:

-- If evolution ran during a GNOME session, the evolution-wombat process 
   did not exit when the user logged out of the desktop.

-- For folders marked for Offline Synchronization: if a user moved a
   message from a Local Folder to an IMAP folder while in
   Offline mode, the message was not present in either folder after
   returning to Online mode.
 
   This update fixes this problem. Email messages that have been lost 
   this way may still be present in the following path: 

   ~/evolution/&amp;lt;NAME_OF_MAIL_STORE&amp;gt;/ \
   &amp;lt;path-to-folder-via-subfolder-directories&amp;gt;/ \
   &amp;lt;temporary-uid-of-message&amp;gt;

If this bug has affected you it may be possible to recover data by
examining the contents of this directory.

All users of evolution should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0102">CVE-2005-0102</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238002" comment="evolution is earlier than 0:1.4.5-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238004" comment="evolution-devel is earlier than 0:1.4.5-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050256" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:256: glibc security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:256-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-256.html" />
	<description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

It was discovered that the use of LD_DEBUG, LD_SHOW_AUXV, and
LD_DYNAMIC_WEAK were not restricted for a setuid program. A local user
could utilize this flaw to gain information, such as the list of symbols
used by the program. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1453 to this issue.

This erratum addresses the following bugs in the GNU C Library:

- fix stack alignment in IA-32 clone
- fix double free in globfree
- fix fnmatch to avoid jumping based on unitialized memory read
- fix fseekpos after ungetc
- fix TZ env var handling if the variable ends with + or -
- avoid depending on values read from unitialized memory in strtold
  on certain architectures
- fix mapping alignment computation in dl-load
- fix i486+ strncat inline assembly
- make gethostid/sethostid work on bi-arch platforms
- fix ppc64 getcontext/swapcontext
- fix pthread_exit if called after pthread_create, but before the created
  thread actually started
- fix return values for tgamma (+-0)
- fix handling of very long lines in /etc/hosts
- avoid page aliasing of thread stacks on AMD64
- avoid busy loop in malloc if concurrent with fork
- allow putenv and setenv in shared library constructors
- fix restoring of CCR in swapcontext and getcontext on ppc64
- avoid using sigaction (SIGPIPE, ...) in syslog implementation

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1453">CVE-2004-1453</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256002" comment="glibc is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256003" comment="glibc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256004" comment="glibc-common is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256005" comment="glibc-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256006" comment="glibc-devel is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256007" comment="glibc-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256008" comment="glibc-headers is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256009" comment="glibc-headers is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256010" comment="glibc-profile is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256011" comment="glibc-profile is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256012" comment="glibc-utils is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256013" comment="glibc-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256014" comment="nptl-devel is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256015" comment="nptl-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256016" comment="nscd is earlier than 0:2.3.2-95.33" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050256017" comment="nscd is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050267" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:267: Evolution security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:267-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-267.html" />
	<description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in Evolution.  If a user tries to save a
carefully crafted meeting or appointment, arbitrary code may be executed as
the user running Evolution. The Common Vulnerabilities and Exposures
project has assigned the name CAN-2005-2550 to this issue.

Additionally, several other format string bugs were found in Evolution. If
a user views a malicious vCard, connects to a malicious LDAP server, or
displays a task list from a malicious remote server, arbitrary code may be
executed as the user running Evolution. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2005-2549 to this issue. Please
note that this issue only affects Red Hat Enterprise Linux 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-29" />
        <updated date="2005-08-29" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2549">CVE-2005-2549</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2550">CVE-2005-2550</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050267002" comment="evolution is earlier than 0:1.4.5-16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050267004" comment="evolution-devel is earlier than 0:1.4.5-16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050267007" comment="evolution is earlier than 0:2.0.2-16.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050267008" comment="evolution-devel is earlier than 0:2.0.2-16.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050271" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:271: HelixPlayer security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-271.html" />
	<description>HelixPlayer is a media player.

A stack based buffer overflow bug was found in HelixPlayer's Synchronized
Multimedia Integration Language (SMIL) file processor. An attacker could
create a specially crafted SMIL file which would execute arbitrary code
when opened by a user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0455 to this issue.

A buffer overflow bug was found in the way HelixPlayer decodes WAV files.
An attacker could create a specially crafted WAV file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0611 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer 1.0.3 which is not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0455">CVE-2005-0455</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0611">CVE-2005-0611</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050271002" comment="HelixPlayer is earlier than 1:1.0.3-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050277" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:277: mozilla security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:277-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-277.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the Mozilla string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Please note that other security issues have been found that affect Mozilla.
These other issues have a lower severity, and are therefore planned to be
released as additional security updates in the future.

Users of Mozilla should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255">CVE-2005-0255</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277002" comment="mozilla is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277004" comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277006" comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277008" comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277010" comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277012" comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277014" comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277016" comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277018" comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050277020" comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050293" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:293: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:293-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-293.html" />
	<description>The following security issues were fixed:

The Vicam USB driver did not use the copy_from_user function to access
userspace, crossing security boundaries. (CAN-2004-0075)

The ext3 and jfs code did not properly initialize journal descriptor
blocks.  A privileged local user could read portions of kernel memory.
(CAN-2004-0177)

The terminal layer did not properly lock line discipline changes or pending
IO.  An unprivileged local user could read portions of kernel memory, or
cause a denial of service (system crash). (CAN-2004-0814)

A race condition was discovered.  Local users could use this flaw to read
the environment variables of another process that is still spawning via
/proc/.../cmdline. (CAN-2004-1058)

A flaw in the execve() syscall handling was discovered, allowing a local
user to read setuid ELF binaries that should otherwise be protected by
standard permissions. (CAN-2004-1073).  Red Hat originally reported this
as being fixed by RHSA-2004:549, but the associated fix was missing from
that update.

Keith Owens reported a flaw in the Itanium unw_unwind_to_user() function.
A local user could use this flaw to cause a denial of service (system
crash) on the Itanium architecture. (CAN-2005-0135)

A missing Itanium syscall table entry could allow an unprivileged
local user to cause a denial of service (system crash) on the Itanium
architecture. (CAN-2005-0137)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architectures was discovered.  A local user could use this flaw to
access privileged IO ports. (CAN-2005-0204)

A flaw was discovered in the Linux PPP driver.  On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 was
discovered that left a pointer to a freed tty structure.  A local user
could potentially use this flaw to cause a denial of service (system crash)
or possibly gain read or write access to ttys that should normally be
prevented. (CAN-2005-0403)

A flaw in fragment queuing was discovered affecting the netfilter
subsystem.  On systems configured to filter or process network packets (for
example those configured to do firewalling), a remote attacker could send a
carefully crafted set of fragmented packets to a machine and cause a denial
of service (system crash).  In order to sucessfully exploit this flaw, the
attacker would need to know (or guess) some aspects of the firewall ruleset
in place on the target system to be able to craft the right fragmented
packets. (CAN-2005-0449)

Missing validation of an epoll_wait() system call parameter could allow
a local user to cause a denial of service (system crash) on the IBM S/390
and zSeries architectures. (CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered.  A local
user could potentially use this flaw to cause a denial of service (system
crash). (CAN-2005-0749)

A flaw was discovered in the bluetooth driver system.  On system where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

In addition to the security issues listed above, there was an important
fix made to the handling of the msync() system call for a particular case
in which the call could return without queuing modified mmap()'ed data for
file system update. (BZ 147969)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

Red Hat Enterprise Linux 3 users are advised to upgrade their kernels to
the packages associated with their machine architectures/configurations

Please note that the fix for CAN-2005-0449 required changing the
external symbol linkages (kernel module ABI) for the ip_defrag()
and ip_ct_gather_frags() functions.  Any third-party module using either
of these would also need to be fixed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-22" />
        <updated date="2005-05-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075">CVE-2004-0075</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177">CVE-2004-0177</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0814">CVE-2004-0814</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1058">CVE-2004-1058</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1073">CVE-2004-1073</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0135">CVE-2005-0135</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0137">CVE-2005-0137</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0204">CVE-2005-0204</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0384">CVE-2005-0384</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0403">CVE-2005-0403</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0449">CVE-2005-0449</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0736">CVE-2005-0736</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0749">CVE-2005-0749</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0750">CVE-2005-0750</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293002" comment="kernel is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293004" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-BOOT is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293006" comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293008" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293010" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293012" comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293014" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-smp-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293016" comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-source is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050293018" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050294" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:294: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 5
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:294-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-294.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

This is the fifth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - support for 2-TB partitions on block devices
  - support for new disk, network, and USB devices
  - support for clustered APIC mode on AMD64 NUMA systems
  - netdump support on AMD64, Intel EM64T, Itanium, and ppc64 systems
  - diskdump support on sym53c8xx and SATA piix/promise adapters
  - NMI switch support on AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 3.

Some key areas affected by these fixes include the kernel's networking,
SATA, TTY, and USB subsystems, as well as the architecture-dependent
handling under the ia64, ppc64, and x86_64 directories.  Scalability
improvements were made primarily in the memory management and file
system areas.

A flaw in offset handling in the xattr file system code backported to
Red Hat Enterprise Linux 3 was fixed.  On 64-bit systems, a user who
can access an ext3 extended-attribute-enabled file system could cause
a denial of service (system crash).  This issue is rated as having a
moderate security impact (CAN-2005-0757).

The following device drivers have been upgraded to new versions:

  3c59x ------ LK1.1.18
  3w-9xxx ---- 2.24.00.011fw (new in Update 5)
  3w-xxxx ---- 1.02.00.037
  8139too ---- (upstream 2.4.29)
  b44 -------- 0.95
  cciss ------ v2.4.54.RH1
  e100 ------- 3.3.6-k2
  e1000 ------ 5.6.10.1-k2
  lpfcdfc ---- 1.0.13 (new in Update 5)
  tg3 -------- 3.22RH

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0757">CVE-2005-0757</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294002" comment="kernel is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294004" comment="kernel-BOOT is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-BOOT is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294006" comment="kernel-doc is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294008" comment="kernel-hugemem is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294010" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294012" comment="kernel-smp is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294014" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-smp-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294016" comment="kernel-source is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-source is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050294018" comment="kernel-unsupported is earlier than 0:2.4.21-32.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050300" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:300: libexif security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:300-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-300.html" />
	<description>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

A bug was found in the way libexif parses EXIF tags. An attacker could
create a carefully crafted EXIF image file which could cause image viewers
linked against libexif to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0664 to this issue.

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0664">CVE-2005-0664</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050300002" comment="libexif is earlier than 0:0.5.12-5.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050300003" comment="libexif is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050300004" comment="libexif-devel is earlier than 0:0.5.12-5.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050300005" comment="libexif-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050306" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:306: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:306-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-306.html" />
	<description>The ethereal package is a program for monitoring network traffic.


A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.

A buffer overflow flaw was discovered in the Etheric dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0704 to this issue.

The GPRS-LLC dissector could crash if the "ignore cipher bit" option was
set. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0705 to this issue.

A buffer overflow flaw was discovered in the 3GPP2 A11 dissector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0699 to this issue.

A buffer overflow flaw was discovered in the IAPP dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0739 to this issue.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-18" />
        <updated date="2005-03-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0699">CVE-2005-0699</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0704">CVE-2005-0704</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0705">CVE-2005-0705</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0739">CVE-2005-0739</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0765">CVE-2005-0765</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0766">CVE-2005-0766</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050306002" comment="ethereal is earlier than 0:0.10.10-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050306004" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050306007" comment="ethereal is earlier than 0:0.10.10-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050306008" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050307" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:307: kdelibs security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:307-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-307.html" />
	<description>The kdelibs package provides libraries for the K Desktop Environment.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

Users of KDE should upgrade to these erratum packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-06" />
        <updated date="2005-04-06" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0396">CVE-2005-0396</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050307002" comment="kdelibs is earlier than 6:3.1.3-6.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050307004" comment="kdelibs-devel is earlier than 6:3.1.3-6.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050320" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:320: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:320-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-320.html" />
	<description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

Additionally, a bug was fixed which caused ImageMagick(TM) to occasionally
segfault when writing TIFF images to standard output.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0397">CVE-2005-0397</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050320002" comment="ImageMagick is earlier than 0:6.0.7.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050320004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050320006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050320008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050320010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050323" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:323: mozilla security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:323-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-323.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1380 to this issue.

A bug was found in the way Mozilla allowed plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0232 to this issue.

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0149 to
this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0147 to this issue.

A bug was found in the way Mozilla handles certain start tags followed by a
NULL character.  A malicious web page could cause Mozilla to crash when
viewed by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1613 to this issue.

A bug was found in the way Mozilla sets file permissions when installing
XPI packages.  It is possible for an XPI package to install some files
world readable or writable, allowing a malicious local user to steal
information or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0906 to
this issue.

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0141 to this issue.

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0144 to this issue.

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.4.4 and additional backported patches to correct
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0906">CVE-2004-0906</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1380">CVE-2004-1380</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1613">CVE-2004-1613</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0141">CVE-2005-0141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144">CVE-2005-0144</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0147">CVE-2005-0147</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149">CVE-2005-0149</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0232">CVE-2005-0232</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399">CVE-2005-0399</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323002" comment="mozilla is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323004" comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323006" comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323008" comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323010" comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323012" comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323014" comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323016" comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323018" comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050323020" comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050325" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:325: kdelibs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:325-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-325.html" />
	<description>The kdelibs package provides libraries for the K Desktop Environment.

The International Domain Name (IDN) support in the Konqueror browser
allowed remote attackers to spoof domain names using punycode encoded
domain names.  Such domain names are decoded in URLs and SSL certificates
in a way that uses homograph characters from other character sets, which
facilitates phishing attacks. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0237 to this issue.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

A flaw in the dcopidlng script was discovered. The dcopidlng script would
create temporary files with predictable filenames which could allow local
users to overwrite arbitrary files via a symlink attack. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0365 to this issue.

Users of KDE should upgrade to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0237">CVE-2005-0237</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0365">CVE-2005-0365</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0396">CVE-2005-0396</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050325002" comment="kdelibs is earlier than 6:3.3.1-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050325004" comment="kdelibs-devel is earlier than 6:3.3.1-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050327" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:327: telnet security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:327-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-327.html" />
	<description>The telnet package provides a command line telnet client. The telnet-server
package includes a telnet daemon, telnetd, that supports remote login to
the host machine.

Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468
and CAN-2005-0469 to these issues.

Additionally, the following bugs have been fixed in these erratum packages
for Red Hat Enterprise Linux 2.1 and Red Hat Enterprise Linux 3:

- telnetd could loop on an error in the child side process

- There was a race condition in telnetd on a wtmp lock on some occasions

- The command line in the process table was sometimes too long and caused
bad output from the ps command

- The 8-bit binary option was not working

Users of telnet should upgrade to this updated package, which contains
backported patches to correct these issues.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468">CVE-2005-0468</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469">CVE-2005-0469</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327002" comment="telnet is earlier than 1:0.17-26.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327004" comment="telnet-server is earlier than 1:0.17-26.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327007" comment="telnet is earlier than 1:0.17-31.EL4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327008" comment="telnet-server is earlier than 1:0.17-31.EL4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050330" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:330: krb5 security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:330-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-330.html" />
	<description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

The krb5-workstation package includes a Kerberos-aware telnet client. 
Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468 and
CAN-2005-0469 to these issues.

Users of krb5 should update to these erratum packages which contain a
backported patch to correct this issue.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0468">CVE-2005-0468</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0469">CVE-2005-0469</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330002" comment="krb5 is earlier than 0:1.2.7-42" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330004" comment="krb5-devel is earlier than 0:1.2.7-42" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330006" comment="krb5-libs is earlier than 0:1.2.7-42" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330008" comment="krb5-server is earlier than 0:1.2.7-42" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330010" comment="krb5-workstation is earlier than 0:1.2.7-42" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330013" comment="krb5 is earlier than 0:1.3.4-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330014" comment="krb5-devel is earlier than 0:1.3.4-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330015" comment="krb5-libs is earlier than 0:1.3.4-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330016" comment="krb5-server is earlier than 0:1.3.4-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050330017" comment="krb5-workstation is earlier than 0:1.3.4-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050331" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:331: XFree86 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:331-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-331.html" />
	<description>XFree86 is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
malicious XPM file that would execute arbitrary code if opened by a victim
using an application linked to the vulnerable library. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0605 to this issue.

The updated XFree86 packages also address the following minor issues:

- Updated XFree86-4.3.0-keyboard-disable-ioport-access-v3.patch to make
  warning messages less alarmist.

- Backported XFree86-4.3.0-libX11-stack-overflow.patch from xorg-x11-6.8.1
  packaging to fix stack overflow in libX11, which was discovered by new
  security features of gcc4.

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0605">CVE-2005-0605</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331002" comment="XFree86 is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331003" comment="XFree86 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331004" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331006" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331008" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331009" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331010" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331011" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331012" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331013" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331014" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331015" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331016" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331017" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331018" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331019" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331020" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331021" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331022" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331023" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331024" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331025" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331026" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331027" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331028" comment="XFree86-Xnest is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331029" comment="XFree86-Xnest is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331030" comment="XFree86-Xvfb is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331031" comment="XFree86-Xvfb is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331032" comment="XFree86-base-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331033" comment="XFree86-base-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331034" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331035" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331036" comment="XFree86-devel is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331037" comment="XFree86-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331038" comment="XFree86-doc is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331039" comment="XFree86-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331040" comment="XFree86-font-utils is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331041" comment="XFree86-font-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331042" comment="XFree86-libs is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331043" comment="XFree86-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331044" comment="XFree86-libs-data is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331045" comment="XFree86-libs-data is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331046" comment="XFree86-sdk is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331047" comment="XFree86-sdk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331048" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331049" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331050" comment="XFree86-tools is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331051" comment="XFree86-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331052" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331053" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331054" comment="XFree86-twm is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331055" comment="XFree86-twm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331056" comment="XFree86-xauth is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331057" comment="XFree86-xauth is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331058" comment="XFree86-xdm is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331059" comment="XFree86-xdm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331060" comment="XFree86-xfs is earlier than 0:4.3.0-81.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050331061" comment="XFree86-xfs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050332" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:332: xloadimage security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:332-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-332.html" />
	<description>The xloadimage utility displays images in an X Window System window,
loads images into the root window, or writes images into a file.
Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM,
and XBM).

A flaw was discovered in xloadimage where filenames were not properly
quoted when calling the gunzip command.  An attacker could create a file
with a carefully crafted filename so that it would execute arbitrary
commands if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0638 to
this issue.

Another bug in xloadimage would cause it to crash if called with certain
invalid TIFF, PNM, PBM, or PPM file names.

All users of xloadimage should upgrade to this erratum package which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-04-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0638">CVE-2005-0638</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050332002" comment="xloadimage is earlier than 0:4.1-34.RHEL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050332005" comment="xloadimage is earlier than 0:4.1-34.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050334" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:334: mysql security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:334-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-334.html" />
	<description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes several security risks in the MySQL server.

Stefano Di Paola discovered two bugs in the way MySQL handles user-defined
functions. A user with the ability to create and execute a user defined
function could potentially execute arbitrary code on the MySQL server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2005-0709 and CAN-2005-0710 to these issues.

Stefano Di Paola also discovered a bug in the way MySQL creates temporary
tables. A local user could create a specially crafted symlink which could
result in the MySQL server overwriting a file which it has write access to.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-0711 to this issue.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0709">CVE-2005-0709</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0710">CVE-2005-0710</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0711">CVE-2005-0711</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334002" comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334003" comment="mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334004" comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334005" comment="mysql-bench is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334006" comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334007" comment="mysql-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334009" comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334003" comment="mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334010" comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334005" comment="mysql-bench is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334011" comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334007" comment="mysql-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334012" comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050334013" comment="mysql-server is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050335" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:335: mozilla security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:335-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-335.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. (CAN-2005-0147)

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. (CAN-2004-1380)

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. (CAN-2005-0149)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Mozilla saves temporary files. Temporary files
are saved with world readable permissions, which could allow a local
malicious user to view potentially sensitive data. (CAN-2005-0142)

A bug was found in the way Mozilla handles synthetic middle click events. 
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

A bug was found in the way Mozilla processes XUL content.  If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. (CAN-2005-0141)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. (CAN-2005-0144)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can display the secure site icon by loading a binary
file from a secured site. (CAN-2005-0143)

A bug was found in the way Mozilla displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.6 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1380">CVE-2004-1380</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0141">CVE-2005-0141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142">CVE-2005-0142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0143">CVE-2005-0143</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144">CVE-2005-0144</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0146">CVE-2005-0146</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149">CVE-2005-0149</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399">CVE-2005-0399</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401">CVE-2005-0401</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335002" comment="devhelp is earlier than 0:0.9.2-2.4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335003" comment="devhelp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335004" comment="evolution is earlier than 0:2.0.2-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335006" comment="mozilla is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335008" comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335009" comment="devhelp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335010" comment="evolution-devel is earlier than 0:2.0.2-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335012" comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335014" comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335016" comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335018" comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335020" comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335022" comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335024" comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335026" comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335028" comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050336" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:336: firefox security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:336-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-336.html" />
	<description>Mozilla Firefox is an open source Web browser.

A buffer overflow bug was found in the way Firefox processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Firefox processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0401 to this issue.

A bug was found in the way Firefox bookmarks content to the sidebar. If a
user can be tricked into bookmarking a malicious web page into the sidebar
panel, that page could execute arbitrary programs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0402 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399">CVE-2005-0399</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401">CVE-2005-0401</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0402">CVE-2005-0402</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050336002" comment="firefox is earlier than 0:1.0.2-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050337" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:337: thunderbird security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:337-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-337.html" />
	<description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A buffer overflow bug was found in the way Thunderbird processes GIF
images. It is possible for an attacker to create a specially crafted GIF
image, which when viewed by a victim will execute arbitrary code as the
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0399 to this issue.

A bug was found in the Thunderbird string handling functions. If a
malicious website is able to exhaust a system's memory, it becomes possible
to execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Users of Thunderbird are advised to upgrade to this updated package which
contains Thunderbird version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399">CVE-2005-0399</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255">CVE-2005-0255</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050337002" comment="thunderbird is earlier than 0:1.0.2-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050340" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:340: curl security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:340-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-340.html" />
	<description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and
Dict servers, using any of the supported protocols. cURL is designed
to work without user interaction or any kind of interactivity. 

Multiple buffer overflow bugs were found in the way curl processes base64
encoded replies. If a victim can be tricked into visiting a URL with curl,
a malicious web server could execute arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0490 to this issue.

All users of curl are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0490">CVE-2005-0490</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340002" comment="curl is earlier than 0:7.10.6-6.rhel3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340004" comment="curl-devel is earlier than 0:7.10.6-6.rhel3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340007" comment="curl is earlier than 0:7.12.1-5.rhel4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340008" comment="curl-devel is earlier than 0:7.12.1-5.rhel4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050343" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:343: gdk-pixbuf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:343-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-343.html" />
	<description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gdk-pixbuf. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gdk-pixbuf are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0891">CVE-2005-0891</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343002" comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343009" comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050344" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:344: gtk2 security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:344-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-344.html" />
	<description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

A bug was found in the way gtk2 processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gtk2. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gtk2 are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0891">CVE-2005-0891</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344002" comment="gtk2 is earlier than 0:2.2.4-15" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344004" comment="gtk2-devel is earlier than 0:2.2.4-15" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344007" comment="gtk2 is earlier than 0:2.4.13-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344008" comment="gtk2-devel is earlier than 0:2.4.13-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050345" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:345: slocate security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:345-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-345.html" />
	<description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- Files with a size of 2 GB and larger were not entered into the slocate
  database.

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems).

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2499">CVE-2005-2499</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050345002" comment="slocate is earlier than 0:2.7-3.RHEL3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050345003" comment="slocate is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050346" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:346: slocate security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:346-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-346.html" />
	<description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems.)

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

- The default configuration excluded /mnt/floppy, but not /media.

- The default configuration did not exclude nfs4 file systems.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2499">CVE-2005-2499</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050346002" comment="slocate is earlier than 0:2.7-13.el4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050345003" comment="slocate is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050354" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:354: tetex security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:354-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-354.html" />
	<description>TeTeX is an implementation of TeX for Linux or UNIX systems. TeX takes
a text file and a set of formatting commands as input and creates a
typesetter-independent .dvi (DeVice Independent) file as output.

A number of security flaws have been found affecting libraries used
internally within teTeX.  An attacker who has the ability to trick a user
into processing a malicious file with teTeX could cause teTeX to crash or
possibly execute arbitrary code. 

A number of integer overflow bugs that affect Xpdf were discovered. The
teTeX package contains a copy of the Xpdf code used for parsing PDF files
and is therefore affected by these bugs. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0888 and
CAN-2004-1125 to these issues.

A number of integer overflow bugs that affect libtiff were discovered.  The
teTeX package contains an internal copy of libtiff used for parsing TIFF
image files and is therefore affected by these bugs.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0803, CAN-2004-0804 and CAN-2004-0886 to these issues.

Also latex2html is added to package tetex-latex for 64bit platforms.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803">CVE-2004-0803</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804">CVE-2004-0804</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886">CVE-2004-0886</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888">CVE-2004-0888</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354002" comment="tetex is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354004" comment="tetex-afm is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-afm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354006" comment="tetex-dvips is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354008" comment="tetex-fonts is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354010" comment="tetex-latex is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-latex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050354012" comment="tetex-xdvi is earlier than 0:1.0.7-67.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-xdvi is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050357" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:357: gzip security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:357-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-357.html" />
	<description>The gzip package contains the GNU gzip data compression program.

A bug was found in the way zgrep processes file names. If a user can be
tricked into running zgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running zgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0758 to this issue.

A bug was found in the way gunzip modifies permissions of files being
decompressed. A local attacker with write permissions in the directory in
which a victim is decompressing a file could remove the file being written
and replace it with a hard link to a different file owned by the victim. 
gunzip then gives the linked file the permissions of the uncompressed file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0988 to this issue.

A directory traversal bug was found in the way gunzip processes the -N
flag. If a victim decompresses a file with the -N flag, gunzip fails to
sanitize the path which could result in a file owned by the victim being
overwritten. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1228 to this issue.

Users of gzip should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0758">CVE-2005-0758</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988">CVE-2005-0988</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228">CVE-2005-1228</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050357002" comment="gzip is earlier than 0:1.3.3-12.rhel3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050357005" comment="gzip is earlier than 0:1.3.3-15.rhel4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050358" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:358: exim security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:358-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-358.html" />
	<description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet.

An integer overflow flaw was found in PCRE, a Perl-compatible regular
expression library included within Exim.  A local user could create a
maliciously crafted regular expression in such as way that they could gain
the privileges of the 'exim' user.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2491 to this issue.  These
erratum packages change Exim to use the system PCRE library instead of the
internal one.  

These packages also fix a minor flaw where the Exim Monitor was incorrectly
computing free space on very large file systems.

Users should upgrade to these erratum packages and also ensure they have
updated the system PCRE library, for which erratum packages are available
seperately in RHSA-2005:761</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491">CVE-2005-2491</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050358002" comment="exim is earlier than 0:4.43-1.RHEL4.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050358004" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050358006" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-mon is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050358008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050361" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:361: vixie-cron security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:361-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-361.html" />
	<description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is
possible for a local attacker to execute the crontab command in such a way
that they can view the contents of another user's crontab file. The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1038 to
this issue. 

Additionally, this update addresses the following issues:

o Fixed improper limits on filename and command line lengths 
o Improved PAM access control conforming to EAL certification requirements
o Improved reliability when running in a chroot environment
o Mail recipient name checking disabled by default, can be re-enabled 
o Added '-p' "permit all crontabs" option to disable crontab mode checking

All users of vixie-cron should upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1038">CVE-2005-1038</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050361002" comment="vixie-cron is earlier than 4:4.1-36.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050365" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:365: gaim security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:365-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-365.html" />
	<description>The Gaim application is a multi-protocol instant messaging client.

A buffer overflow bug was found in the way gaim escapes HTML. It is
possible that a remote attacker could send a specially crafted message to a
Gaim client, causing it to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0965 to this issue.

A bug was found in several of gaim's IRC processing functions. These
functions fail to properly remove various markup tags within an IRC
message. It is possible that a remote attacker could send a specially
crafted message to a Gaim client connected to an IRC server, causing it to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0966 to this issue.

A bug was found in gaim's Jabber message parser. It is possible for a
remote Jabber user to send a specially crafted message to a Gaim client,
causing it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0967 to this issue.

In addition to these denial of service issues, multiple minor upstream
bugfixes are included in this update.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.2.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-12" />
        <updated date="2005-04-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0965">CVE-2005-0965</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0966">CVE-2005-0966</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0967">CVE-2005-0967</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050365002" comment="gaim is earlier than 1:1.2.1-4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050365005" comment="gaim is earlier than 1:1.2.1-4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050366" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:366: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:366-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-366.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

A flaw in the fib_seq_start function was discovered. A local user could use
this flaw to cause a denial of service (system crash) via /proc/net/route.
(CAN-2005-1041)

A flaw in the tmpfs file system was discovered. A local user could use this
flaw to cause a denial of service (system crash). (CAN-2005-0977)

An integer overflow flaw was found when writing to a sysfs file. A local
user could use this flaw to overwrite kernel memory, causing a denial of
service (system crash) or arbitrary code execution. (CAN-2005-0867)

Keith Owens reported a flaw in the Itanium unw_unwind_to_user function. A
local user could use this flaw to cause a denial of service (system crash)
on Itanium architectures. (CAN-2005-0135)

A flaw in the NFS client O_DIRECT error case handling was discovered. A
local user could use this flaw to cause a denial of service (system crash).
(CAN-2005-0207)

A small memory leak when defragmenting local packets was discovered that
affected the Linux 2.6 kernel netfilter subsystem.  A local user could send
a large number of carefully crafted fragments leading to memory exhaustion
(CAN-2005-0210)

A flaw was discovered in the Linux PPP driver. On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw was discovered in the ext2 file system code. When a new directory is
created, the ext2 block written to disk is not initialized, which could
lead to an information leak if a disk image is made available to
unprivileged users. (CAN-2005-0400)

A flaw in fragment queuing was discovered that affected the Linux kernel
netfilter subsystem. On systems configured to filter or process network
packets (e.g. firewalling), a remote attacker could send a carefully
crafted set of fragmented packets to a machine and cause a denial of
service (system crash). In order to sucessfully exploit this flaw, the
attacker would need to know or guess some aspects of the firewall ruleset
on the target system. (CAN-2005-0449)

A number of flaws were found in the Linux 2.6 kernel. A local user could
use these flaws to read kernel memory or cause a denial of service (crash).
(CAN-2005-0529, CAN-2005-0530, CAN-2005-0531)

An integer overflow in sys_epoll_wait in eventpoll.c was discovered. A
local user could use this flaw to overwrite low kernel memory. This memory
is usually unused, not usually resulting in a security consequence.
(CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered. A local
user could potentially use this flaw to cause a denial of service (crash).
(CAN-2005-0749)

A flaw was discovered in the bluetooth driver system. On systems where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

A race condition was discovered that affected the Radeon DRI driver. A
local user who has DRI privileges on a Radeon graphics card may be able to
use this flaw to gain root privileges. (CAN-2005-0767)

Multiple range checking flaws were discovered in the iso9660 file system
handler. An attacker could create a malicious file system image which would
cause a denial or service or potentially execute arbitrary code if mounted.
(CAN-2005-0815)

A flaw was discovered when setting line discipline on a serial tty. A local
user may be able to use this flaw to inject mouse movements or keystrokes
when another user is logged in. (CAN-2005-0839)

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.

Please note that</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-08-09" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0135">CVE-2005-0135</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0207">CVE-2005-0207</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0210">CVE-2005-0210</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0384">CVE-2005-0384</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0400">CVE-2005-0400</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0449">CVE-2005-0449</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0529">CVE-2005-0529</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0530">CVE-2005-0530</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0531">CVE-2005-0531</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0736">CVE-2005-0736</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0749">CVE-2005-0749</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0750">CVE-2005-0750</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0767">CVE-2005-0767</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0815">CVE-2005-0815</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0839">CVE-2005-0839</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0867">CVE-2005-0867</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0977">CVE-2005-0977</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1041">CVE-2005-1041</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366002" comment="kernel is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366004" comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366006" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366008" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092009" comment="kernel-hugemem-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366010" comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366012" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092013" comment="kernel-smp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050366014" comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050373" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:373: net-snmp security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:373-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-373.html" />
	<description>SNMP (Simple Network Management Protocol) is a protocol used for network
management.

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet which will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc which can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally the following bugs have been fixed:
 - snmpwalk no longer hangs when a non-existant pid is listed. 
 - snmpd no longer segfaults due to incorrect handling of lmSensors. 
 - an incorrect assignment leading to invalid values in ASN mibs has been
   fixed.
 - on systems running a 64-bit kernel, the values in /proc/net/dev no 
   longer become too large to fit in a 32-bit object. 
 - the net-snmp-devel packages correctly depend on elfutils-libelf-devel.
 - large file systems are correctly handled
 - snmp daemon now reports gigabit Ethernet speeds correctly
 - fixed consistency between IP adresses and hostnames in configuration file

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2177">CVE-2005-2177</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1740">CVE-2005-1740</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4837">CVE-2005-4837</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373002" comment="net-snmp is earlier than 0:5.0.9-2.30E.19" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373003" comment="net-snmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373004" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373005" comment="net-snmp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373006" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373007" comment="net-snmp-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373008" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373009" comment="net-snmp-perl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373010" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-utils is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050375" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:375: openoffice.org security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:375-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-375.html" />
	<description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap based buffer overflow bug was found in the OpenOffice.org DOC file
processor. An attacker could create a carefully crafted DOC file in such a
way that it could cause OpenOffice.org to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0941 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0941">CVE-2005-0941</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375002" comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375004" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375006" comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375009" comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375010" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375011" comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375012" comment="openoffice.org-kde is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375013" comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050375007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050377" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:377: sharutils security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:377-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-377.html" />
	<description>The sharutils package contains a set of tools for encoding and decoding
packages of files in binary or text format.

A stack based overflow bug was found in the way shar handles the -o option.
If a user can be tricked into running a specially crafted command, it could
lead to arbitrary code execution.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1772 to this issue.
Please note that this issue does not affect Red Hat Enterprise Linux 4.

Two buffer overflow bugs were found in sharutils. If an attacker can place
a malicious 'wc' command on a victim's machine, or trick a victim into
running a specially crafted command, it could lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1773 to this issue.

A bug was found in the way unshar creates temporary files. A local user
could use symlinks to overwrite arbitrary files the victim running unshar
has write access to. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0990 to this issue.

All users of sharutils should upgrade to this updated package, which
includes backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1772">CVE-2004-1772</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1773">CVE-2004-1773</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0990">CVE-2005-0990</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050377002" comment="sharutils is earlier than 0:4.2.1-16.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050377005" comment="sharutils is earlier than 0:4.2.1-22.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050378" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:378: cpio security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:378-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-378.html" />
	<description>GNU cpio copies files into or out of a cpio or tar archive. 

A race condition bug was found in cpio. It is possible for a local
malicious user to modify the permissions of a local file if they have write
access to a directory in which a cpio archive is being extracted. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1111 to this issue.

Additionally, this update adds cpio support for archives larger than 2GB.
However, the size of individual files within an archive is limited to 4GB.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1111">CVE-2005-1111</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050378002" comment="cpio is earlier than 0:2.5-4.RHEL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050378005" comment="cpio is earlier than 0:2.5-8.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050381" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:381: nasm security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:381-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-381.html" />
	<description>NASM is an 80x86 assembler.

Two stack based buffer overflow bugs have been found in nasm. An attacker
could create an ASM file in such a way that when compiled by a victim,
could execute arbitrary code on their machine. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1287
and CAN-2005-1194 to these issues.

All users of nasm are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1287">CVE-2004-1287</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1194">CVE-2005-1194</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381002" comment="nasm is earlier than 0:0.98.35-3.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm is earlier than 0:0.98.38-3.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381006" comment="nasm-doc is earlier than 0:0.98.38-3.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381008" comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050381009" comment="nasm-rdoff is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050383" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:383: firefox security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:383-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-383.html" />
	<description>Mozilla Firefox is an open source Web browser.

Vladimir V. Perepelitsa discovered a bug in the way Firefox handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Omar Khan discovered a bug in the way Firefox processes the PLUGINSPAGE
tag. It is possible for a malicious web page to trick a user into pressing
the "manual install" button for an unknown plugin leading to arbitrary
javascript code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0752 to this issue.

Doron Rosenberg discovered a bug in the way Firefox displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1153 to this issue.

A bug was found in the way Firefox handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1154 to
this issue.

Michael Krax discovered a bug in the way Firefox handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1155 to this issue.

Michael Krax discovered a bug in the way Firefox installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and steal sensitive information.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2005-1156 and CAN-2005-1157 to these issues. 

Kohei Yoshino discovered a bug in the way Firefox opens links in its
sidebar. A malicious web page could construct a link in such a way that,
when clicked on, could execute arbitrary javascript with elevated
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1158 to this issue.

A bug was found in the way Firefox validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1159 to this issue.

A bug was found in the way the Firefox privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1160 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.3 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-21" />
        <updated date="2005-04-21" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0752">CVE-2005-0752</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989">CVE-2005-0989</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153">CVE-2005-1153</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1154">CVE-2005-1154</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1155">CVE-2005-1155</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156">CVE-2005-1156</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157">CVE-2005-1157</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1158">CVE-2005-1158</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1159">CVE-2005-1159</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1160">CVE-2005-1160</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050383002" comment="firefox is earlier than 0:1.0.3-1.4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050384" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:384: Mozilla security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:384-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-384.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found with the way Mozilla displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0143 CAN-2005-0593)

A bug was found in the way Mozilla handles synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

Several bugs were found with the way Mozilla handles temporary files. A
local user could view sensitive temporary information or delete arbitrary
files. (CAN-2005-0142 CAN-2005-0578)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

Several bugs were found in the way Mozilla displays alert dialogs. It is
possible for a malicious webserver or website to trick a user into thinking
the dialog window is being generated from a trusted site. (CAN-2005-0586
CAN-2005-0591 CAN-2005-0585 CAN-2005-0590 CAN-2005-0584)

A bug was found in the Mozilla javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed,
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Mozilla allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527)

A bug was found in the way Mozilla handles anonymous functions during
regular expression string replacement. It is possible for a malicious web
page to capture a random block of browser memory. (CAN-2005-0989)

A bug was found in the way Mozilla displays pop-up windows. If a user
choses to open a pop-up window whose URL is malicious javascript, the
script will be executed with elevated privileges. (CAN-2005-1153)

A bug was found in the way Mozilla installed search plugins. If a user
chooses to install a search plugin from a malicious site, the new plugin
could silently overwrite an existing plugin. This could allow the malicious
plugin to execute arbitrary code and stealm sensitive information.
(CAN-2005-1156 CAN-2005-1157)

Several bugs were found in the Mozilla javascript engine. A malicious web
page could leverage these issues to execute javascript with elevated
privileges or steal sensitive information. (CAN-2005-1154 CAN-2005-1155
CAN-2005-1159 CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1156">CVE-2004-1156</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142">CVE-2005-0142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0143">CVE-2005-0143</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0146">CVE-2005-0146</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0231">CVE-2005-0231</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0232">CVE-2005-0232</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233">CVE-2005-0233</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401">CVE-2005-0401</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0527">CVE-2005-0527</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0578">CVE-2005-0578</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0584">CVE-2005-0584</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585">CVE-2005-0585</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0586">CVE-2005-0586</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0588">CVE-2005-0588</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0590">CVE-2005-0590</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0591">CVE-2005-0591</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593">CVE-2005-0593</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989">CVE-2005-0989</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153">CVE-2005-1153</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1154">CVE-2005-1154</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1155">CVE-2005-1155</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156">CVE-2005-1156</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157">CVE-2005-1157</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1159">CVE-2005-1159</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1160">CVE-2005-1160</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384002" comment="mozilla is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384004" comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384006" comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384008" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384010" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384012" comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384014" comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384016" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384018" comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050384020" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050386" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:386: Mozilla security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:386-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-386.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Vladimir V. Perepelitsa discovered a bug in the way Mozilla handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Doron Rosenberg discovered a bug in the way Mozilla displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges.
(CAN-2005-1153)

A bug was found in the way Mozilla handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. (CAN-2005-1154)

Michael Krax discovered a bug in the way Mozilla handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges.
(CAN-2005-1155)

Michael Krax discovered a bug in the way Mozilla installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and stealm sensitive
information. (CAN-2005-1156 CAN-2005-1157)

A bug was found in the way Mozilla validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Mozilla privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. (CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989">CVE-2005-0989</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153">CVE-2005-1153</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1154">CVE-2005-1154</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1155">CVE-2005-1155</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156">CVE-2005-1156</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157">CVE-2005-1157</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1159">CVE-2005-1159</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1160">CVE-2005-1160</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386002" comment="devhelp is earlier than 0:0.9.2-2.4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335003" comment="devhelp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386004" comment="mozilla is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386006" comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050335009" comment="devhelp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386008" comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386010" comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386012" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386014" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386016" comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386018" comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386020" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386022" comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050386024" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050387" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:387: cvs security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:387-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-387.html" />
	<description>CVS (Concurrent Version System) is a version control system.

A buffer overflow bug was found in the way the CVS client processes version
and author information. If a user can be tricked into connecting to a
malicious CVS server, an attacker could execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0753 to this issue.

Additionally, a bug was found in which CVS freed an invalid pointer.
However, this issue does not appear to be exploitable.

All users of cvs should upgrade to this updated package, which includes a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0753">CVE-2005-0753</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050387002" comment="cvs is earlier than 0:1.11.2-27" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050387005" comment="cvs is earlier than 0:1.11.17-7.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050392" version="304" class="patch">
      <metadata>
        <title>RHSA-2005:392: HelixPlayer security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:392-04" ref_url="https://rhn.redhat.com/errata/RHSA-2005-392.html" />
	<description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes RAM files.
An attacker could create a specially crafted RAM file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0755 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.4 and is not vulnerable to this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-20" />
        <updated date="2005-04-20" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0755">CVE-2005-0755</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050392002" comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050393" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:393: kdelibs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:393-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-393.html" />
	<description>KDE is a graphical desktop environment for the X Window System. Konqueror
is the file manager for the K Desktop Environment. 

A source code audit performed by the KDE security team discovered several
vulnerabilities in the PCX and other image file format readers.

A buffer overflow was found in the kimgio library for KDE 3.4.0.  An
attacker could create a carefully crafted PCX image in such a way that it
would cause kimgio to execute arbitrary code when processing the image. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1046 to this issue.

All users of kdelibs should upgrade to these updated packages, which
contain a backported security patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1046">CVE-2005-1046</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050393002" comment="kdelibs is earlier than 6:3.3.1-3.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050393004" comment="kdelibs-devel is earlier than 6:3.3.1-3.10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050395" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:395: net-snmp security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:395-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-395.html" />
	<description>SNMP (Simple Network Management Protocol) is a protocol used for network
management. 

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet that will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc that can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally, the following bugs have been fixed:
- The lmSensors are correctly recognized, snmp deamon no longer segfaults
- The larger swap partition sizes are correctly reported 
- Querying hrSWInstalledLastUpdateTime no longer crashes the snmp deamon
- Fixed error building ASN.1 representation
- The 64-bit network counters correctly wrap
- Large file systems are correctly handled
- Snmptrapd initscript correctly reads options from its configuration 
  file /etc/snmp/snmptrapd.options 
- Snmp deamon no longer crashes when restarted using the agentX 
  protocol
- snmp daemon now reports gigabit Ethernet speeds correctly
- MAC adresses are shown when requested instead of IP adresses

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1740">CVE-2005-1740</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2177">CVE-2005-2177</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4837">CVE-2005-4837</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050395002" comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373003" comment="net-snmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050395004" comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373005" comment="net-snmp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050395006" comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373007" comment="net-snmp-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050395008" comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373009" comment="net-snmp-perl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050395010" comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-utils is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050396" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:396: xorg-x11 security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:396-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-396.html" />
	<description>X.org is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow bugs were found in the way X.org parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue. 

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-13" />
        <updated date="2005-09-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495">CVE-2005-2495</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396004" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396006" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396008" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396010" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-Xnest is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396012" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396014" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396016" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396018" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396022" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396024" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396026" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-sdk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396028" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396030" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-twm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396032" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-xauth is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396034" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-xdm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050396036" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050198039" comment="xorg-x11-xfs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050397" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:397: evolution security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:397-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-397.html" />
	<description>Evolution is a GNOME-based collection of personal information management
(PIM) tools.

A bug was found in the way Evolution displays mail messages. It is possible
that an attacker could create a specially crafted mail message that when
opened by a victim causes Evolution to stop responding. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0806 to this issue.

A bug was also found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue.  On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default.  Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

All users of evolution should upgrade to these updated packages, which
include backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0102">CVE-2005-0102</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0806">CVE-2005-0806</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050397002" comment="evolution is earlier than 0:2.0.2-16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050397004" comment="evolution-devel is earlier than 0:2.0.2-16" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050405" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:405: PHP security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:405-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-405.html" />
	<description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way that it could execute arbitrary instructions when processed by PHP.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
 to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- The security fixes in RHSA-2004-687 to the "unserializer" code introduced
some performance issues.

- In the gd extension, the "imagecopymerge" function did not correctly
handle transparency.  The original image was being obscured in the
resultant image.

- In the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1392">CVE-2004-1392</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0524">CVE-2005-0524</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0525">CVE-2005-0525</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1042">CVE-2005-1042</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1043">CVE-2005-1043</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405002" comment="php is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405004" comment="php-devel is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405006" comment="php-imap is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-imap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405008" comment="php-ldap is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-ldap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405010" comment="php-mysql is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405012" comment="php-odbc is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-odbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050405014" comment="php-pgsql is earlier than 0:4.3.2-23.ent" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-pgsql is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050406" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:406: PHP security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:406-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-406.html" />
	<description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way it could execute arbitrary instructions when processed by PHP. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- some performance issues in the unserialize() function have been fixed

- the behaviour of the interpreter when handling integer overflow during
conversion of a floating variable to an integer has been reverted to match
the behaviour used upstream; the integer will now be wrapped rather than
truncated

- a fix for the virtual() function in the Apache httpd module which would
flush the response prematurely

- the hard-coded default "safe mode" setting is now "disabled" rather than
"enabled"; to match the default /etc/php.ini setting

- in the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1392">CVE-2004-1392</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0524">CVE-2005-0524</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0525">CVE-2005-0525</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1042">CVE-2005-1042</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1043">CVE-2005-1043</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406002" comment="php is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406004" comment="php-devel is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406006" comment="php-domxml is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-domxml is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406008" comment="php-gd is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-gd is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406010" comment="php-imap is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-imap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406012" comment="php-ldap is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-ldap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406014" comment="php-mbstring is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-mbstring is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406016" comment="php-mysql is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406018" comment="php-ncurses is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-ncurses is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406020" comment="php-odbc is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-odbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406022" comment="php-pear is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-pear is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406024" comment="php-pgsql is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-pgsql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406026" comment="php-snmp is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-snmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050406028" comment="php-xmlrpc is earlier than 0:4.3.9-3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-xmlrpc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050408" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:408: cyrus-imapd security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:408-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-408.html" />
	<description>The cyrus-imapd package contains the core of the Cyrus IMAP server.

Several buffer overflow bugs were found in cyrus-imapd. It is possible that
an authenticated malicious user could cause the imap server to crash.
Additionally, a peer news admin could potentially execute arbitrary code on
the imap server when news is received using the fetchnews command. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages, which
contain cyrus-imapd version 2.2.12 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0546">CVE-2005-0546</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408002" comment="cyrus-imapd is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408003" comment="cyrus-imapd is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408004" comment="cyrus-imapd-devel is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408005" comment="cyrus-imapd-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408006" comment="cyrus-imapd-murder is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408007" comment="cyrus-imapd-murder is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408008" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408009" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408010" comment="cyrus-imapd-utils is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408011" comment="cyrus-imapd-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408012" comment="perl-Cyrus is earlier than 0:2.2.12-3.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050408013" comment="perl-Cyrus is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050410" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:410: gftp security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:410-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-410.html" />
	<description>gFTP is a multi-threaded FTP client for the X Window System.

A directory traversal bug was found in gFTP. If a user can be tricked into
downloading a file from a malicious ftp server, it is possible to overwrite
arbitrary files owned by the victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0372 to
this issue.

Users of gftp should upgrade to this updated package, which contains a
backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372">CVE-2005-0372</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050410002" comment="gftp is earlier than 1:2.0.14-4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050410005" comment="gftp is earlier than 1:2.0.17-5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050412" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:412: openmotif security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:412-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-412.html" />
	<description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.  

An integer overflow flaw was found in libXpm, which is used to decode XPM
(X PixMap) images.  A vulnerable version of this library was
found within OpenMotif.  An attacker could create a carefully crafted XPM
file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0605 to
this issue.

Users of OpenMotif are advised to upgrade to these erratum packages, which
contains a backported security patch to the embedded libXpm library.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0605">CVE-2005-0605</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412002" comment="openmotif is earlier than 0:2.2.3-5.RHEL3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412003" comment="openmotif is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412004" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412005" comment="openmotif21 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412006" comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412007" comment="openmotif-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412009" comment="openmotif is earlier than 0:2.2.3-9.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412003" comment="openmotif is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412010" comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412005" comment="openmotif21 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412011" comment="openmotif-devel is earlier than 0:2.2.3-9.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050412007" comment="openmotif-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050413" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:413: ImageMagick security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:413-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-413.html" />
	<description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A heap based buffer overflow bug was found in the way ImageMagick parses
PNM files. An attacker could execute arbitrary code on a victim's machine
if they were able to trick the victim into opening a specially crafted PNM
file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1275 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-25" />
        <updated date="2005-05-25" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1275">CVE-2005-1275</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413002" comment="ImageMagick is earlier than 0:5.5.6-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413004" comment="ImageMagick-c++ is earlier than 0:5.5.6-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413006" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413008" comment="ImageMagick-devel is earlier than 0:5.5.6-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413010" comment="ImageMagick-perl is earlier than 0:5.5.6-14" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413013" comment="ImageMagick is earlier than 0:6.0.7.1-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413014" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413015" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413016" comment="ImageMagick-devel is earlier than 0:6.0.7.1-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050413017" comment="ImageMagick-perl is earlier than 0:6.0.7.1-11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050415" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:415: squid security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:415-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-415.html" />
	<description>Squid is a full-featured Web proxy cache.  
 
A race condition bug was found in the way Squid handles the now obsolete
Set-Cookie header. It is possible that Squid can leak Set-Cookie header
information to other clients connecting to Squid. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0626 to this issue. Please note that this issue only affected Red
Hat Enterprise Linux 4. 
 
A bug was found in the way Squid handles PUT and POST requests. It is
possible for an authorised remote user to cause a failed PUT or POST
request which can cause Squid to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0718 to
this issue.
 
A bug was found in the way Squid processes errors in the access control
list. It is possible that an error in the access control list could give
users more access than intended. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1345 to this issue.
 
A bug was found in the way Squid handles access to the cachemgr.cgi script. 
It is possible for an authorised remote user to bypass access control
lists with this flaw. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-1999-0710 to this issue.
 
A bug was found in the way Squid handles DNS replies.  If the port Squid
uses for DNS requests is not protected by a firewall it is possible for a
remote attacker to spoof DNS replies, possibly redirecting a user to
spoofed or malicious content. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1519 to this issue. 
 
Additionally this update fixes the following bugs:   
 - LDAP Authentication fails with an assertion error when using Red Hat
Enterprise Linux 4 
 
Users of Squid should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-14" />
        <updated date="2005-06-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0710">CVE-1999-0710</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0626">CVE-2005-0626</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0718">CVE-2005-0718</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1345">CVE-2005-1345</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1519">CVE-2005-1519</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050415002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050415005" comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050417" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:417: tcpdump security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:417-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-417.html" />
	<description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

The tcpdump utility can now write a file larger than 2 GB. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1278">CVE-2005-1278</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1279">CVE-2005-1279</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1280">CVE-2005-1280</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417002" comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417003" comment="tcpdump is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417004" comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417005" comment="arpwatch is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417006" comment="libpcap is earlier than 14:0.8.3-9.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050417007" comment="libpcap is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050420" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:420: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 1
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:420-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-420.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

This is the first regular kernel update to Red Hat Enterprise Linux 4.

A flaw affecting the auditing code was discovered.  On Itanium
architectures a local user could use this flaw to cause a denial of service
(crash).  This issue is rated as having important security impact
(CAN-2005-0136). 

A flaw was discovered in the servicing of a raw device ioctl.  A local user
who has access to raw devices could use this flaw to write to kernel memory
and cause a denial of service or potentially gain privileges.  This issue
is rated as having moderate security impact (CAN-2005-1264). 

A flaw in fragment forwarding was discovered that affected the netfilter
subsystem for certain network interface cards. A remote attacker could send
a set of bad fragments and cause a denial of service (system crash). Acenic
and SunGEM network interfaces were the only adapters affected, which are in
widespread use. (CAN-2005-0209)

A flaw in the futex functions was discovered affecting the Linux 2.6
kernel.  A local user could use this flaw to cause a denial of service
(system crash). (CAN-2005-0937)

New features introduced by this update include:
- Fixed TCP BIC congestion handling.
- Diskdump support for more controllers (megaraid, SATA)
- Device mapper multipath support
- AMD64 dual core support.
- Intel ICH7 hardware support.

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.

The following device drivers have been upgraded to new versions:
 ata_piix -------- 1.03
 bonding --------- 2.6.1
 e1000 ----------- 5.6.10.1-k2-NAPI
 e100 ------------ 3.3.6-k2-NAPI
 ibmveth --------- 1.03
 libata ---------- 1.02 to 1.10
 lpfc ------------ 0:8.0.16 to 0:8.0.16.6_x2
 megaraid_mbox --- 2.20.4.0 to 2.20.4.5
 megaraid_mm ----- 2.20.2.0-rh1 to 2.20.2.5
 sata_nv --------- 0.03 to 0.6
 sata_promise ---- 1.00 to 1.01
 sata_sil -------- 0.8
 sata_sis -------- 0.5
 sata_svw -------- 1.05
 sata_sx4 -------- 0.7
 sata_via -------- 1.0
 sata_vsc -------- 1.0
 tg3 ------------- 3.22-rh
 ipw2100 --------- 1.0.3
 ipw2200 --------- 1.0.0

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-08-09" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0136">CVE-2005-0136</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0209">CVE-2005-0209</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0937">CVE-2005-0937</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1264">CVE-2005-1264</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3107">CVE-2005-3107</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420002" comment="kernel is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420004" comment="kernel-devel is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420006" comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420008" comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092009" comment="kernel-hugemem-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420010" comment="kernel-smp is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420012" comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050092013" comment="kernel-smp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050420014" comment="kernel-doc is earlier than 0:2.6.9-11.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050421" version="303" class="patch">
      <metadata>
        <title>RHSA-2005:421: tcpdump security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:421-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-421.html" />
	<description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

Additionally, the tcpdump utility can now write a file larger than 2 GB,
pa