<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-05-02T14:35:25
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20050009" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:009: kdelibs, kdebase security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-009.html" />
          <reference source="CVE" ref_id="CVE-2004-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1158.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
          <reference source="CVE" ref_id="CVE-2005-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0078.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.

Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1158
to this issue.

A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-0078 to this issue.

All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1158.html">CVE-2004-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0078.html">CVE-2005-0078</cve>
                <bugzilla href="http://bugzilla.redhat.com/142393" id="142393">CAN-2004-1158 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145381" id="145381">CAN-2005-0078 password bypass in kde screensaver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146760" id="146760">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009002" comment="kdelibs is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009004" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009006" comment="kdebase is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009007" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009008" comment="kdebase-devel is earlier than 6:3.1.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050010" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:010: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:010-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-010.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  It is possible
that a malicious user could create a file containing a specially crafted
modeline which could cause arbitrary command execution when viewed by a
victim.  Please note that this issue only affects users who have modelines
and filetype plugins enabled, which is not the default.  The  Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1138
to this issue.

All users of VIM are advised to upgrade to these erratum packages,
which contain a backported patch for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-05" />
        <updated date="2005-01-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
                <bugzilla href="http://bugzilla.redhat.com/142444" id="142444">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010002" comment="vim is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010004" comment="vim-common is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050010008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050011" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:011: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-011.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-02" />
        <updated date="2005-02-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/142952" id="142952">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145481" id="145481">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050011002" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050012" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:012: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:012-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-012.html" />
          <reference source="CVE" ref_id="CVE-2004-0971" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0971.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

Additionally a temporary file bug was found in the Kerberos krb5-send-pr
program.  It is possible that an attacker could create a temporary file
that would allow an arbitrary file to be overwritten which the victim has
write access to.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0971 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-19" />
        <updated date="2005-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0971.html">CVE-2004-0971</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/136304" id="136304">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140066" id="140066">CAN-2004-0971 temporary file vulnerabilities in krb5-send-pr script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142902" id="142902">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012006" comment="krb5-libs is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012004" comment="krb5-devel is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012008" comment="krb5-server is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012002" comment="krb5 is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050012010" comment="krb5-workstation is earlier than 0:1.2.7-38" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050013" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:013: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-013.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package.  An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.

A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.

The lppasswd utility ignores write errors when modifying the CUPS passwd
file.  A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.

In addition to these security issues, two other problems not relating
to security have been fixed:

Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop.  This has been fixed in later
versions of CUPS, and has been backported in these updated packages.

The cancel-cups(1) man page is a symbolic link to another man page.  The
target of this link has been corrected.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
                <bugzilla href="http://bugzilla.redhat.com/136973" id="136973">cancel-cups man page missing from errata package</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143087" id="143087">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143566" id="143566">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013004" comment="cups-devel is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013006" comment="cups-libs is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050013002" comment="cups is earlier than 1:1.1.17-13.3.22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050018" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:018: xpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-018.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf packages should upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/143499" id="143499">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018002" comment="xpdf is earlier than 1:2.02-9.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050019" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:019: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-019.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

iDEFENSE has reported an integer overflow bug that affects libtiff. An
attacker who has the ability to trick a user into opening a malicious TIFF
file could cause the application linked to libtiff to crash or possibly
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin reported another integer overflow in the tiffdump 
utility.  An atacker who has the ability to trick a user into opening a
malicious TIFF file with tiffdump could possibly execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/143505" id="143505">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143577" id="143577">CVE-2004-1183 libtiff: tiffdump integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019002" comment="libtiff is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050019004" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050021" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:021: kdegraphics security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:021-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-021.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1307.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
    
    <description>The kdegraphics package contains graphics applications for the K Desktop
Environment.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. The kfax application contains a copy of
the libtiff code used for parsing TIFF files and is therefore affected by
these bugs. An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause kfax to crash or possibly execute arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found. The kfax application contains a copy of the libtiff code used
for parsing TIFF files and is therefore affected by these bugs. An attacker
who has the ability to trick a user into opening a malicious TIFF file
could cause kfax to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0803 to this issue.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-14" />
        <updated date="2005-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1307.html">CVE-2004-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
                <bugzilla href="http://bugzilla.redhat.com/135466" id="135466">CAN-2004-0803 buffer overflows in libtiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135470" id="135470">CAN-2004-0886 multiple integer overflows in libtiff</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021002" comment="kdegraphics is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050021004" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050025" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:025: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-025.html" />
          <reference source="CVE" ref_id="CVE-2005-0021" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0021.html" />
          <reference source="CVE" ref_id="CVE-2005-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0022.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. 

A buffer overflow was discovered in the spa_base64_to_bits function in
Exim, as originally obtained from Samba code.  If SPA authentication is
enabled, a remote attacker may be able to exploit this vulnerability to
execute arbitrary code as the 'exim' user.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to
this issue.  Please note that SPA authentication is not enabled by default
in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and
dns_build_reverse functions in Exim.  A local user can trigger these flaws
by executing exim with carefully crafted command line arguments and may be
able to gain the privileges of the 'exim' account.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0021.html">CVE-2005-0021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0022.html">CVE-2005-0022</cve>
                <bugzilla href="http://bugzilla.redhat.com/144099" id="144099">CAN-2005-0021 exim security issues (CAN-2005-0022)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025002" comment="exim is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050026" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:026: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:026-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-026.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/144257" id="144257">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145055" id="145055">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026006" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026002" comment="tetex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026012" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026014" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026004" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026008" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050026010" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050032" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:032: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:032-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-032.html" />
          <reference source="CVE" ref_id="CVE-2004-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1018.html" />
          <reference source="CVE" ref_id="CVE-2004-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1019.html" />
          <reference source="CVE" ref_id="CVE-2004-1065" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1065.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP. PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow. An attacker could create a carefully crafted image file in such
a way which, if parsed by a PHP script using the exif extension, could
cause a crash or potentially execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions. These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1018.html">CVE-2004-1018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1019.html">CVE-2004-1019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1065.html">CVE-2004-1065</cve>
                <bugzilla href="http://bugzilla.redhat.com/141136" id="141136">CAN-2004-1018 Multiple issues in PHP (CAN-2004-1019 CAN-2004-1020)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032028" comment="php-gd is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032016" comment="php-odbc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032012" comment="php-mysql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032002" comment="php is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032022" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032024" comment="php-mbstring is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032014" comment="php-pgsql is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032004" comment="php-devel is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032026" comment="php-ncurses is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032018" comment="php-snmp is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032008" comment="php-imap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032006" comment="php-pear is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032020" comment="php-domxml is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050032010" comment="php-ldap is earlier than 0:4.3.9-3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050033" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:033: alsa-lib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-033.html" />
          <reference source="CVE" ref_id="CVE-2005-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0087.html" />
    
    <description>The alsa-lib package provides a library of functions for communication with
kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack
execution protection to be disabled for the libasound.so library.  
The effect of this flaw is that stack execution protection, through NX or
Exec-Shield, would be disabled for any application linked to libasound. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a
patched version of the library which correctly enables stack execution
protection.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0087.html">CVE-2005-0087</cve>
                <bugzilla href="http://bugzilla.redhat.com/144518" id="144518">CAN-2005-0087 alsa-lib disables stack protection for it's users</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033004" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033005" comment="alsa-lib-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050033002" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050033003" comment="alsa-lib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050034" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:034: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:034-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-034.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf. An attacker could construct a carefully crafted PDF file that could
cause Xpdf to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org).  Red Hat Enterprise Linux 4 contained a fix for this
issue, but it was found to be incomplete and left 64-bit architectures
vulnerable.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0206 to this issue.

All users of Xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135066" id="135066">PDF is displayed garbled, older xpdf works</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144197" id="144197">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145052" id="145052">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147498" id="147498">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050034002" comment="xpdf is earlier than 1:3.00-11.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050035" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:035: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:035-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-035.html" />
          <reference source="CVE" ref_id="CVE-2004-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1308.html" />
          <reference source="CVE" ref_id="CVE-2004-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1183.html" />
    
    <description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

infamous41md discovered integer overflow flaws in libtiff.  An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to overflow a heap buffer when the
file was opened by a victim.  Due to the nature of the overflow it is
unlikely that it is possible to use this flaw to execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin discovered an integer overflow flaw in libtiff.  An
attacker could create a carefully crafted TIFF file in such a way that it
could cause an application linked with libtiff to crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1308.html">CVE-2004-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1183.html">CVE-2004-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/144185" id="144185">CAN-2004-1308 LibTIFF Directory Entry Count Integer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144186" id="144186">CAN-2004-1183 libtiff integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035002" comment="libtiff is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050035004" comment="libtiff-devel is earlier than 0:3.6.1-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050036" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:036: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-036.html" />
          <reference source="CVE" ref_id="CVE-2004-1138" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1138.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  An attacker
could create a text file containing a specially crafted modeline which
could cause arbitrary command execution when viewed by a victim using VIM. 
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-1138 to this issue.  Please note that this issue only affects
users who have modelines and filetype plugins enabled, which is not the
default.  

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM.  A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue. 

All users of VIM are advised to upgrade to these erratum packages,
which contain backported patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1138.html">CVE-2004-1138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144187" id="144187">CAN-2004-1138 vim arbitrary command execution vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144880" id="144880">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036006" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036002" comment="vim is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036010" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036004" comment="vim-common is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050036008" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050037" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:037: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-037.html" />
          <reference source="CVE" ref_id="CVE-2004-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1139.html" />
          <reference source="CVE" ref_id="CVE-2004-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1140.html" />
          <reference source="CVE" ref_id="CVE-2004-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1141.html" />
          <reference source="CVE" ref_id="CVE-2004-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1142.html" />
          <reference source="CVE" ref_id="CVE-2005-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0006.html" />
          <reference source="CVE" ref_id="CVE-2005-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0007.html" />
          <reference source="CVE" ref_id="CVE-2005-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0008.html" />
          <reference source="CVE" ref_id="CVE-2005-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0009.html" />
          <reference source="CVE" ref_id="CVE-2005-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0010.html" />
          <reference source="CVE" ref_id="CVE-2005-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0084.html" />
    
    <description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization.  (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084) 

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1139.html">CVE-2004-1139</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1140.html">CVE-2004-1140</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1141.html">CVE-2004-1141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1142.html">CVE-2004-1142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0006.html">CVE-2005-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0007.html">CVE-2005-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0008.html">CVE-2005-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0009.html">CVE-2005-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0010.html">CVE-2005-0010</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0084.html">CVE-2005-0084</cve>
                <bugzilla href="http://bugzilla.redhat.com/144188" id="144188">CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145483" id="145483">CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050037002" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050038" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:038: mozilla security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:038-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-038.html" />
          <reference source="CVE" ref_id="CVE-2004-1316" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1316.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way
Mozilla handles NNTP URLs.  If a user visits a malicious web page or is
convinced to click on a malicious link, it may be possible for an attacker
to execute arbitrary code on the victim's machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1316.html">CVE-2004-1316</cve>
                <bugzilla href="http://bugzilla.redhat.com/143994" id="143994">CAN-2004-1316 buffer overflow in mozilla</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038018" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038014" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038016" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038010" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038002" comment="mozilla is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038020" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038006" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038004" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038012" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050038008" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050039" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:039: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-039.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences. A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document. An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments. These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144683" id="144683">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039002" comment="enscript is earlier than 0:1.6.1-24.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050040" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:040: enscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:040-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-040.html" />
          <reference source="CVE" ref_id="CVE-2004-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1184.html" />
          <reference source="CVE" ref_id="CVE-2004-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1185.html" />
          <reference source="CVE" ref_id="CVE-2004-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1186.html" />
    
    <description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences.  A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document.  An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments.  These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1184.html">CVE-2004-1184</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1185.html">CVE-2004-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1186.html">CVE-2004-1186</cve>
                <bugzilla href="http://bugzilla.redhat.com/144686" id="144686">CAN-2004-1184 multiple security issues in enscript (CAN-2004-1185 CAN-2004-1186)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050040002" comment="enscript is earlier than 0:1.6.1-28.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050043" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:043: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:043-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-043.html" />
          <reference source="CVE" ref_id="CVE-2004-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0791.html" />
          <reference source="CVE" ref_id="CVE-2004-1074" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1074.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2004-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1237.html" />
          <reference source="CVE" ref_id="CVE-2005-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0003.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1235 to
this issue.

A flaw was discovered where an executable could cause a VMA overlap leading
to a crash.  A local user could trigger this flaw by creating a carefully
crafted a.out binary on 32-bit systems or a carefully crafted ELF binary
on Itanium systems.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0003 to this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0001 to this issue. A patch
that coincidentally fixed this issue was committed to the Update 4 kernel
release in December 2004.  Therefore Red Hat Enterprise Linux 3 kernels
provided by RHBA-2004:550 and subsequent updates are not vulnerable to
this issue.

A flaw in the system call filtering code in the audit subsystem included
in Red Hat Enterprise Linux 3 allowed a local user to cause a crash when
auditing was enabled.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1237 to this issue.

Olaf Kirch discovered that the recent security fixes for cmsg_len handling
(CAN-2004-1016) broke 32-bit compatibility on 64-bit platforms such as
AMD64 and Intel EM64T. A patch to correct this issue is included.

A recent Internet Draft by Fernando Gont recommended that ICMP Source
Quench messages be ignored by hosts.  A patch to ignore these messages is
included.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-18" />
        <updated date="2005-01-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0791.html">CVE-2004-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1074.html">CVE-2004-1074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1237.html">CVE-2004-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0003.html">CVE-2005-0003</cve>
                <bugzilla href="http://bugzilla.redhat.com/132245" id="132245">CAN-2004-1237 Kernel panic when stopping Lotus Domino 6.52</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141996" id="141996">CAN-2004-1237 instant kernel panic from one line perl program - BAD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142091" id="142091">CAN-2004-1237 kernel oops captured, system hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142442" id="142442">CAN-2004-1237 kernel panic ( __audit_get_target)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143866" id="143866">CAN-2004-1237 kernel panic caused by auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144048" id="144048">CAN-2004-1237 kernel panic when Oracle agentctl is run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144134" id="144134">CAN-2004-1235 isec.pl uselib() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144784" id="144784">CAN-2005-0003 huge vma-in-executable bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043004" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043002" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043006" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043018" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043014" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050043012" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050045" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:045: krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-045.html" />
          <reference source="CVE" ref_id="CVE-2004-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1189.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1189.html">CVE-2004-1189</cve>
                <bugzilla href="http://bugzilla.redhat.com/144196" id="144196">CAN-2004-1189 buffer overflow in krb5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045006" comment="krb5-libs is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045004" comment="krb5-devel is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045008" comment="krb5-server is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045002" comment="krb5 is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050045010" comment="krb5-workstation is earlier than 0:1.3.4-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050049" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:049: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:049-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-049.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit these buffer overflow
vulnerabilities on x86 architectures.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145102" id="145102">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049004" comment="cups-devel is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049006" comment="cups-libs is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050049002" comment="cups is earlier than 1:1.1.17-13.3.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050053" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:053: CUPS security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:053-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-053.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2004-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1267.html" />
          <reference source="CVE" ref_id="CVE-2004-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1268.html" />
          <reference source="CVE" ref_id="CVE-2004-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1269.html" />
          <reference source="CVE" ref_id="CVE-2004-1270" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1270.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects CUPS due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause CUPS to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects the CUPS pdftops filter due to a shared codebase.  An attacker
who has the ability to send a malicious PDF file to a printer could
possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the ParseCommand function in the
hpgltops program. An attacker who has the ability to send a malicious HPGL
file to a printer could possibly execute arbitrary code as the "lp" user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1267 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

The lppasswd utility was found to ignore write errors when modifying the
CUPS passwd file. A local user who is able to fill the associated file
system could corrupt the CUPS password file or prevent future uses of
lppasswd. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility was found to not verify that the passwd.new file is
different from STDERR, which could allow local users to control output to
passwd.new via certain user input that triggers an error message. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1270 to this issue.

All users of cups should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1267.html">CVE-2004-1267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1268.html">CVE-2004-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1269.html">CVE-2004-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1270.html">CVE-2004-1270</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144191" id="144191">CAN-2004-1267 Bernstein cups issues (CAN-2004-1268 CAN-2004-1269 CAN-2004-1270)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144194" id="144194">CAN-2004-1125 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145088" id="145088">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147480" id="147480">CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050053002" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050057" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:057: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:057-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-057.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files for GNOME. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

Users should update to this erratum package which contains backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/144210" id="144210">CAN-2004-1125 gpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145054" id="145054">CAN-2005-0064 xpdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147518" id="147518">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057002" comment="gpdf is earlier than 0:2.8.2-4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050059" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:059: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-059.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found when processing the /Encrypt /Length tag.
An attacker could construct a carefully crafted PDF file that could cause
Xpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf package should upgrade to this updated package,
which resolves this issue</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/145049" id="145049">CAN-2005-0064 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050059002" comment="xpdf is earlier than 1:2.02-9.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050060" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:060: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-060.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious webpage
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious Web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious Web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145545" id="145545">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146161" id="146161">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146779" id="146779">CAN-2005-0211 Buffer overflow in WCCP recvfrom() call</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146785" id="146785">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050061" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:061: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:061-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-061.html" />
          <reference source="CVE" ref_id="CVE-2005-0094" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0094.html" />
          <reference source="CVE" ref_id="CVE-2005-0095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0095.html" />
          <reference source="CVE" ref_id="CVE-2005-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0096.html" />
          <reference source="CVE" ref_id="CVE-2005-0097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0097.html" />
          <reference source="CVE" ref_id="CVE-2005-0173" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0173.html" />
          <reference source="CVE" ref_id="CVE-2005-0174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0174.html" />
          <reference source="CVE" ref_id="CVE-2005-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0211" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0211.html" />
          <reference source="CVE" ref_id="CVE-2005-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0241.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious web page
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-11" />
        <updated date="2005-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0094.html">CVE-2005-0094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0095.html">CVE-2005-0095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0096.html">CVE-2005-0096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0097.html">CVE-2005-0097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0173.html">CVE-2005-0173</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0174.html">CVE-2005-0174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0175.html">CVE-2005-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0211.html">CVE-2005-0211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0241.html">CVE-2005-0241</cve>
                <bugzilla href="http://bugzilla.redhat.com/145540" id="145540">CAN-2005-0094 Multiple issues with squid (CAN-2005-0095 CAN-2005-0096 CAN-2005-0097)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146159" id="146159">CAN-2005-0173 Multiple squid issues (CAN-2005-0174 CAN-2005-0175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146780" id="146780">CAN-2005-0241 Correct handling of oversized reply headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050061002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050065" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:065: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:065-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-065.html" />
          <reference source="CVE" ref_id="CVE-2004-1145" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1145.html" />
          <reference source="CVE" ref_id="CVE-2004-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1165.html" />
    
    <description>The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in
the Konqueror web browser. If a user has Java enabled in Konqueror and
visits a malicious website, the website could run a carefully crafted
Java-applet and obtain escalated privileges allowing reading and writing of
arbitrary files with the privileges of the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave.  KDE applications such as
Konqueror could be forced to execute arbitrary FTP commands via a carefully
crafted ftp URL.  The URL could also be crafted in such a way as to send an
arbitrary email via SMTP.  An attacker could make use of this flaw if a
victim visits a malicious web site. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1145.html">CVE-2004-1145</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1165.html">CVE-2004-1165</cve>
                <bugzilla href="http://bugzilla.redhat.com/144211" id="144211">CAN-2004-1145 Konqueror Java Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145938" id="145938">CAN-2004-1165 kioslave command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065002" comment="kdelibs is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050065004" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050066" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:066: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-066.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
          <reference source="CVE" ref_id="CVE-2005-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0064.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that
also affects kpdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects kpdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf which also affects
kpdf due to a shared codebase. An attacker could construct a carefully
crafted PDF file that could cause kpdf to crash or possibly execute
arbitrary code when opened. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0064.html">CVE-2005-0064</cve>
                <bugzilla href="http://bugzilla.redhat.com/144231" id="144231">CAN-2004-1125 kpdf buffer overflows (CAN-2005-0064)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147517" id="147517">CAN-2004-0888 xpdf integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066002" comment="kdegraphics is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050066004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050068" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:068: less security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:068-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-068.html" />
          <reference source="CVE" ref_id="CVE-2005-0086" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0086.html" />
    
    <description>The less utility is a text file browser that resembles more, but has
extended capabilities.

Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue.  Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit this vulnerability on x86
architectures.

All users of the less package should upgrade to this updated package,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0086.html">CVE-2005-0086</cve>
                <bugzilla href="http://bugzilla.redhat.com/145527" id="145527">CAN-2005-0086 less crashes on scrolling of binary files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068002" comment="less is earlier than 0:378-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050068003" comment="less is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050069" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:069: perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:069-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-069.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069002" comment="perl-DBI is earlier than 0:1.32-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050070" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:070: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:070-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-070.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
          <reference source="CVE" ref_id="CVE-2005-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0759.html" />
          <reference source="CVE" ref_id="CVE-2005-0760" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0760.html" />
          <reference source="CVE" ref_id="CVE-2005-0761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0761.html" />
          <reference source="CVE" ref_id="CVE-2005-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0762.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible
that a TIFF image file with an invalid tag could cause ImageMagick to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a
specially crafted TIFF image file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible
that a specially crafted PSD file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser.  It is possible
that an attacker could execute arbitrary code by tricking a user into
opening a specially crafted SGI image file. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0759.html">CVE-2005-0759</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0760.html">CVE-2005-0760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0761.html">CVE-2005-0761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0762.html">CVE-2005-0762</cve>
                <bugzilla href="http://bugzilla.redhat.com/145111" id="145111">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150312" id="150312">CAN-2005-0759 Denial of Service in .tiff images with invalid TAG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150315" id="150315">CAN-2005-0760 Accessing memory outside of image during decoding of TIFF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150323" id="150323">CAN-2005-0761 Bug in parsing PSD files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150327" id="150327">CAN-2005-0762 Buffer overflow in SGI parser</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070004" comment="ImageMagick-devel is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070006" comment="ImageMagick-perl is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070002" comment="ImageMagick is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050070008" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050071" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:071: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:071-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-071.html" />
          <reference source="CVE" ref_id="CVE-2005-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0005.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0005.html">CVE-2005-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/145123" id="145123">CAN-2005-0005 buffer overflow in ImageMagick</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071002" comment="ImageMagick is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050071004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050072" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:072: perl-DBI security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:072-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-072.html" />
          <reference source="CVE" ref_id="CVE-2005-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0077.html" />
    
    <description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0077.html">CVE-2005-0077</cve>
                <bugzilla href="http://bugzilla.redhat.com/145577" id="145577">CAN-2005-0077 perl-DBI insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050072002" comment="perl-DBI is earlier than 0:1.40-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050073" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:073: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:073-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-073.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive.  

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option.  This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

Users of cpio should upgrade to this updated package, which resolves
this issue.

Red Hat would like to thank Mike O'Connor for bringing this issue to our
attention.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/145725" id="145725">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073002" comment="cpio is earlier than 0:2.5-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050074" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:074: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:074-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-074.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory.  This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rexec command failed with "Invalid Argument", because the code
used sigaction() as an unsupported signal.

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

The rexec command prompted for username and password regardless of the
~/.netrc configuration file contents. This updated package contains a patch
that no longer skips the ~/.netrc file. 

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/67361" id="67361">rcp gives incorrect error report when file system writes fai</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/118630" id="118630">rexec fails with "Invalid Argument"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146435" id="146435">RHEL3: rexec prompts for username/password before checking ~/.netrc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146437" id="146437">RHEL3: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146464" id="146464">malicious rsh server can cause rcp to write to arbitrary files (like scp CAN-2004-0175)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074002" comment="rsh is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050074004" comment="rsh-server is earlier than 0:0.17-17.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050080" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:080: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:080-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-080.html" />
          <reference source="CVE" ref_id="CVE-1999-1572" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-1572.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

It was discovered that cpio uses a 0 umask when creating files using the -O
(archive) option. This creates output files with mode 0666 (all can read
and write) regardless of the user's umask setting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-1999-1572 to this issue.

All users of cpio should upgrade to this updated package, which resolves
this issue, and adds support for large files (> 2GB).</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-1572.html">CVE-1999-1572</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145720" id="145720">CAN-1999-1572 cpio insecure file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050080002" comment="cpio is earlier than 0:2.5-3e.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050081" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:081: ghostscript security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:081-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-081.html" />
          <reference source="CVE" ref_id="CVE-2004-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0967.html" />
    
    <description>Ghostscript is a program for displaying PostScript files or printing them
to non-PostScript printers.

A bug was found in the way several of Ghostscript's utility scripts created
temporary files. A local user could cause these utilities to overwrite
files that the victim running the utility has write access to.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2004-0967 to
this issue.

Additionally, this update addresses the following issue:

A problem has been identified in the PDF output driver, which can cause
output to be delayed indefinitely on some systems.  The fix has been
backported from GhostScript 7.07.

All users of ghostscript should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0967.html">CVE-2004-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/97583" id="97583">[7.05-20.1] gs gets stuck reading /dev/random</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136321" id="136321">CAN-2004-0967 temporary file vulnerabilities in various ghostscript scripts.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081002" comment="ghostscript is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081003" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081004" comment="ghostscript-devel is earlier than 0:7.05-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081005" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050081006" comment="hpijs is earlier than 0:1.3-32.1.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050081007" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050090" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:090: htdig security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-090.html" />
          <reference source="CVE" ref_id="CVE-2005-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0085.html" />
    
    <description>The ht://Dig system is a Web search and indexing system for a small domain
or intranet.

Michael Krax reported a cross-site scripting bug affecting htdig. An
attacker could construct a carefully crafted URL which can cause a web
browser to execute malicious script once visited.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-0085
to this issue.

Users of htdig should upgrade to these updated packages, which contain a
backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0085.html">CVE-2005-0085</cve>
                <bugzilla href="http://bugzilla.redhat.com/144261" id="144261">CAN-2005-0085 XSS vulnerability in htdig 3.2.0b6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145649" id="145649">htdig packaging cleanups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090002" comment="htdig is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090003" comment="htdig is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050090004" comment="htdig-web is earlier than 3:3.2.0b6-3.40.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050090005" comment="htdig-web is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050092" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:092: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:092-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-092.html" />
          <reference source="CVE" ref_id="CVE-2004-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1056.html" />
          <reference source="CVE" ref_id="CVE-2004-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1137.html" />
          <reference source="CVE" ref_id="CVE-2004-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1235.html" />
          <reference source="CVE" ref_id="CVE-2005-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0001.html" />
          <reference source="CVE" ref_id="CVE-2005-0090" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0090.html" />
          <reference source="CVE" ref_id="CVE-2005-0091" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0091.html" />
          <reference source="CVE" ref_id="CVE-2005-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0092.html" />
          <reference source="CVE" ref_id="CVE-2005-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0176.html" />
          <reference source="CVE" ref_id="CVE-2005-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0177.html" />
          <reference source="CVE" ref_id="CVE-2005-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0178.html" />
          <reference source="CVE" ref_id="CVE-2005-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0179.html" />
          <reference source="CVE" ref_id="CVE-2005-0180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0180.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered multiple vulnerabilities in the IGMP
functionality.  These flaws could allow a local user to cause a denial of
service (crash) or potentially gain privileges.  Where multicast
applications are being used on a system, these flaws may also allow remote
users to cause a denial of service.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1137 to
this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  (CAN-2005-0001)

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  (CAN-2004-1235)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architecture was discovered.  A local user could use this flaw to write to
privileged IO ports.  (CAN-2005-0204)

The Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not
properly check the DMA lock, which could allow remote attackers or local
users to cause a denial of service (X Server crash) or possibly modify the
video output. (CAN-2004-1056)

OGAWA Hirofumi discovered incorrect tables sizes being used in the
filesystem Native Language Support ASCII translation table.  This could
lead to a denial of service (system crash).  (CAN-2005-0177)

Michael Kerrisk discovered a flaw in the 2.6.9 kernel which allows users to
unlock arbitrary shared memory segments.  This flaw could lead to
applications not behaving as expected.  (CAN-2005-0176)

Improvements in the POSIX signal and tty standards compliance exposed
a race condition.  This flaw can be triggered accidentally by threaded
applications or deliberately by a malicious user and can result in a
denial of service (crash) or in occasional cases give access to a small
random chunk of kernel memory.  (CAN-2005-0178)

The PaX team discovered a flaw in mlockall introduced in the 2.6.9 kernel.
An unprivileged user could use this flaw to cause a denial of service
(CPU and memory consumption or crash).  (CAN-2005-0179)

Brad Spengler discovered multiple flaws in sg_scsi_ioctl in the 2.6 kernel.
An unprivileged user may be able to use this flaw to cause a denial of
service (crash) or possibly other actions.  (CAN-2005-0180)

Kirill Korotaev discovered a missing access check regression in the Red Hat
Enterprise Linux 4 kernel 4GB/4GB split patch.  On systems using the
hugemem kernel, a local unprivileged user could use this flaw to cause a
denial of service (crash).  (CAN-2005-0090)

A flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch can
allow syscalls to read and write arbitrary kernel memory.  On systems using
the hugemem kernel, a local unprivileged user could use this flaw to gain
privileges.  (CAN-2005-0091)

An additional flaw in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split
patch was discovered. On x86 systems using the hugemem kernel, a local
unprivileged user may be able to use this flaw to cause a denial of service
(crash).  (CAN-2005-0092)

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1056.html">CVE-2004-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1137.html">CVE-2004-1137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1235.html">CVE-2004-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0001.html">CVE-2005-0001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0090.html">CVE-2005-0090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0091.html">CVE-2005-0091</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0092.html">CVE-2005-0092</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0176.html">CVE-2005-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0177.html">CVE-2005-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0178.html">CVE-2005-0178</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0179.html">CVE-2005-0179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0180.html">CVE-2005-0180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
                <bugzilla href="http://bugzilla.redhat.com/142670" id="142670">CAN-2004-1137 IGMP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144131" id="144131">CAN-2005-0090 4GB split DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144136" id="144136">CAN-2004-1235 isec.pl do_brk() privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144391" id="144391">CAN-2004-1056 insufficient locking checks in DRM code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144412" id="144412">CAN-2005-0001 page fault @ SMP privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144471" id="144471">CAN-2005-0176 unlock someone elses ipc memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144522" id="144522">CAN-2005-0180 2.6 scsi ioctl integer overflow and information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144528" id="144528">CAN-2005-0179 RLIMIT_MEMLOCK bypass and (2.6) unprivileged user DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144532" id="144532">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144658" id="144658">CAN-2005-0091 4g4g PROT_NONE fix (CAN-2005-0092)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146083" id="146083">20041212 Clear ebp on sysenter return</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146095" id="146095">CAN-2005-0177 nls_ascii incorrect table size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146101" id="146101">CAN-2005-0178 tty/setsid race</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092002" comment="kernel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092006" comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092004" comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050092008" comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050094" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:094: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:094-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-094.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
    
    <description>Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victim's
clipboard. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0146 to this issue.

A bug was found in the way Thunderbird handled cookies when loading content
over HTTP regardless of the user's preference. It is possible that a
particular user could be tracked through the use of malicious mail messages
which load content over HTTP. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0149 to this issue.

Users of Thunderbird are advised to upgrade to this updated package,
which contains Thunderbird version 1.0 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
                <bugzilla href="http://bugzilla.redhat.com/146315" id="146315">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156749" id="156749">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094002" comment="thunderbird is earlier than 0:1.0-1.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050099" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:099: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:099-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-099.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145387" id="145387">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145967" id="145967">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050100" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:100: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-100.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146657" id="146657">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050100002" comment="mod_python is earlier than 0:3.1.3-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050100003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050102" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:102: dbus security update. (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-102.html" />
          <reference source="CVE" ref_id="CVE-2005-0201" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0201.html" />
    
    <description>D-BUS is a system for sending messages between applications. It is
used both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Dan Reed discovered that a user can send and listen to messages on another
user's per-user session bus if they know the address of the socket. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0201 to this issue.  In Red Hat Enterprise Linux 4, the
per-user session bus is only used for printing notifications,  therefore
this issue would only allow a local user to examine or send additional
print notification messages.

Users of dbus are advised to upgrade to these updated packages,
which contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0201.html">CVE-2005-0201</cve>
                <bugzilla href="http://bugzilla.redhat.com/146766" id="146766">CAN-2005-0201 dbus information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102008" comment="dbus-x11 is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102009" comment="dbus-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102010" comment="dbus-python is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102011" comment="dbus-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102004" comment="dbus-devel is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102005" comment="dbus-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102002" comment="dbus is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102003" comment="dbus is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050102006" comment="dbus-glib is earlier than 0:0.22-12.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050102007" comment="dbus-glib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050103" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:103: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-103.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

An unsafe file permission bug was discovered in the rmtree() function in
the File::Path module.  The rmtree() function removes files and directories
in an insecure manner, which could allow a local user to read or delete
arbitrary files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0452 to this issue.

Users of Perl are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/146739" id="146739">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156 )</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146774" id="146774">CAN-2004-0452 File::Path::rmtree() issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103004" comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050103002" comment="perl is earlier than 3:5.8.5-12.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050104" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:104: mod_python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-104.html" />
          <reference source="CVE" ref_id="CVE-2005-0088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0088.html" />
    
    <description>Mod_python is a module that embeds the Python language interpreter within
the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of
mod_python, used to make objects inside modules callable via URL.  
A remote user could visit a carefully crafted URL that would gain access to
objects that should not be visible, leading to an information leak.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package,
which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0088.html">CVE-2005-0088</cve>
                <bugzilla href="http://bugzilla.redhat.com/146655" id="146655">CAN-2005-0088 mod_python information leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050104002" comment="mod_python is earlier than 0:3.0.3-5.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050100003" comment="mod_python is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050105" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:105: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-105.html" />
          <reference source="CVE" ref_id="CVE-2004-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0452.html" />
          <reference source="CVE" ref_id="CVE-2005-0155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0155.html" />
          <reference source="CVE" ref_id="CVE-2005-0156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0156.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Kevin Finisterre discovered a stack based buffer overflow flaw in sperl,
the Perl setuid wrapper. A local user could create a sperl executable
script with a carefully created path name, overflowing the buffer and
leading to root privilege escalation.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0156 to
this issue.

Kevin Finisterre discovered a flaw in sperl which can cause debugging
information to be logged to arbitrary files.  By setting an environment
variable, a local user could cause sperl to create, as root, files with
arbitrary filenames, or append the debugging information to existing files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0155 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-07" />
        <updated date="2005-02-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0452.html">CVE-2004-0452</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0155.html">CVE-2005-0155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0156.html">CVE-2005-0156</cve>
                <bugzilla href="http://bugzilla.redhat.com/140227" id="140227">Potential insecurity in CGI.pm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146737" id="146737">CAN-2005-0155 multiple setuid perl issues (CAN-2005-0156)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105006" comment="perl-CGI is earlier than 2:2.81-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105008" comment="perl-DB_File is earlier than 2:1.804-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105010" comment="perl-suidperl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105004" comment="perl-CPAN is earlier than 2:1.61-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050105002" comment="perl is earlier than 2:5.8.0-89.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050106" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:106: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-106.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH
replaces rlogin and rsh, and provides secure encrypted communications
between two untrusted hosts over an insecure network. X11 connections and
arbitrary TCP/IP ports can also be forwarded over a secure channel. Public
key authentication can be used for "passwordless" access to servers.

The scp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses scp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also correct the following bugs:

On systems where direct ssh access for the root user was disabled by
configuration (setting "PermitRootLogin no"), attempts to guess the root
password could be judged as sucessful or unsucessful by observing a delay.

On systems where the privilege separation feature was turned on, the user
resource limits were not correctly set if the configuration specified to
raise them above the defaults.  It was also not possible to change an
expired password.

Users of openssh should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/120147" id="120147">CAN-2004-0175 malicious ssh server can cause scp to write to arbitrary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124602" id="124602">OpenSSH does not allow users to change expired passwords when privsep is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141642" id="141642">SSH allows attacker to divine root password</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106002" comment="openssh is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050106008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050108" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:108: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:108-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-108.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146649" id="146649">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108004" comment="python-devel is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108008" comment="python-docs is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108010" comment="tkinter is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108002" comment="python is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050108006" comment="python-tools is earlier than 0:2.3.4-14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050109" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:109: python security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-109.html" />
          <reference source="CVE" ref_id="CVE-2005-0089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0089.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer.  This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0089.html">CVE-2005-0089</cve>
                <bugzilla href="http://bugzilla.redhat.com/146645" id="146645">CAN-2005-0089 python SimpleXMLRPCServer security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109004" comment="python-devel is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108005" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109008" comment="python-docs is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108009" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109010" comment="tkinter is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109002" comment="python is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050109006" comment="python-tools is earlier than 0:2.2.3-6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050108007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050110" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:110: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-110.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running emacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146702" id="146702">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110008" comment="emacs-el is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110010" comment="emacs-leim is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110002" comment="emacs is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110006" comment="emacs-common is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110007" comment="emacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050110004" comment="emacs-nox is earlier than 0:21.3-19.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110005" comment="emacs-nox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050112" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:112: emacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:112-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-112.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>Emacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of Emacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running emacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of Emacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146700" id="146700">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112004" comment="emacs-el is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110009" comment="emacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112006" comment="emacs-leim is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110011" comment="emacs-leim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050112002" comment="emacs is earlier than 0:21.3-4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050110003" comment="emacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050122" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:122: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:122-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-122.html" />
          <reference source="CVE" ref_id="CVE-2005-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0069.html" />
    
    <description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM. A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue.

All users of VIM are advised to upgrade to these erratum packages, which
contain a backported patche for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0069.html">CVE-2005-0069</cve>
                <bugzilla href="http://bugzilla.redhat.com/144695" id="144695">CAN-2005-0069 vim unsafe temporary file usage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122002" comment="vim is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122004" comment="vim-common is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050122008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050128" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:128: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:128-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-128.html" />
          <reference source="CVE" ref_id="CVE-2005-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0198.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access
protocols.

A logic error in the CRAM-MD5 code in the University of Washington IMAP
(UW-IMAP) server was discovered.  When Challenge-Response Authentication
Mechanism with MD5 (CRAM-MD5) is enabled, UW-IMAP does not properly enforce
all the required conditions for successful authentication, which could
allow remote attackers to authenticate as arbitrary users.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
 CAN-2005-0198 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-23" />
        <updated date="2005-02-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0198.html">CVE-2005-0198</cve>
                <bugzilla href="http://bugzilla.redhat.com/145469" id="145469">CAN-2005-0198 user validation issue in imap when using CRAM-MD5 authetication</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128006" comment="imap-utils is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128004" comment="imap-devel is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050128002" comment="imap is earlier than 1:2002d-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050132" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:132: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-132.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The Common UNIX Printing System (CUPS) is a print spooler.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect Xpdf.  CUPS contained a copy of the Xpdf code
used for parsing PDF files and was therefore affected by these bugs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2004-0888 to this issue, and Red Hat released erratum
RHSA-2004:543 with updated packages.

It was found that the patch used to correct this issue was not sufficient
and did not fully protect CUPS running on 64-bit architectures.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue. 

These updated packages also include a fix that prevents the CUPS
initscript from being accidentally replaced.

All users of CUPS on 64-bit architectures should upgrade to these updated
packages, which contain a corrected patch and are not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-18" />
        <updated date="2005-02-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135378" id="135378">CAN-2004-0888 xpdf issues affect cups</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132004" comment="cups-devel is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132006" comment="cups-libs is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050132002" comment="cups is earlier than 1:1.1.17-13.3.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050133" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:133: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:133-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-133.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs.  If a user connects to a malicious POP server,
an attacker can execute arbitrary code as the user running xemacs.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146706" id="146706">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133004" comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133005" comment="xemacs-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133010" comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133008" comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133006" comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133007" comment="xemacs-nox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050133002" comment="xemacs is earlier than 0:21.4.15-10.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050134" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:134: xemacs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:134-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-134.html" />
          <reference source="CVE" ref_id="CVE-2005-0100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0100.html" />
    
    <description>XEmacs is a powerful, customizable, self-documenting, modeless text editor.

Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running xemacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.

Users of XEmacs are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0100.html">CVE-2005-0100</cve>
                <bugzilla href="http://bugzilla.redhat.com/146704" id="146704">CAN-2005-0100 Arbitrary code execution in *emacs*</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134006" comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133011" comment="xemacs-info is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134004" comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133009" comment="xemacs-el is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050134002" comment="xemacs is earlier than 0:21.4.13-8.ent.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050133003" comment="xemacs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050135" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:135: squirrelmail security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:135-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-135.html" />
          <reference source="CVE" ref_id="CVE-2005-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0075.html" />
          <reference source="CVE" ref_id="CVE-2005-0103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0103.html" />
          <reference source="CVE" ref_id="CVE-2005-0104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0104.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

Jimmy Conner discovered a missing variable initialization in Squirrelmail.
This flaw could allow potential insecure file inclusions on servers where
the PHP setting "register_globals" is set to "On". This is not a default or
recommended setting.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0075 to this issue.

A URL sanitisation bug was found in Squirrelmail. This flaw could allow a
cross site scripting attack when loading the URL for the sidebar. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0103 to this issue.

A missing variable initialization bug was found in Squirrelmail. This flaw
could allow a cross site scripting attack.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0104 to
this issue.

Users of Squirrelmail are advised to upgrade to this updated package,
which contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0075.html">CVE-2005-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0103.html">CVE-2005-0103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0104.html">CVE-2005-0104</cve>
                <bugzilla href="http://bugzilla.redhat.com/145384" id="145384">CAN-2005-0075 Arbitrary code injection in Squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145964" id="145964">CAN-2005-0103 Multiple issues in squirrelmail (CAN-2005-0104)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050135002" comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050136" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:136: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:136-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-136.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>The mailman package is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147342" id="147342">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136002" comment="mailman is earlier than 3:2.1.5-24.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050137" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:137: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:137-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-137.html" />
          <reference source="CVE" ref_id="CVE-2005-0202" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0202.html" />
    
    <description>Mailman is software to help manage email discussion lists.

A flaw in the true_path function of Mailman was discovered.  A remote
attacker who is a member of a private mailman list could use a carefully
crafted URL and gain access to arbitrary files on the server.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0202 to this issue.  

Note: Mailman installations running on Apache 2.0-based servers are not
vulnerable to this issue.

Users of Mailman should update to these erratum packages that contain a
patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0202.html">CVE-2005-0202</cve>
                <bugzilla href="http://bugzilla.redhat.com/147344" id="147344">CAN-2005-0202 mailman flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050137002" comment="mailman is earlier than 3:2.1.5-31.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050138" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:138: postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:138-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-138.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>A flaw in the LOAD command in PostgreSQL was discovered. A local user
could use this flaw to load arbitrary shared libraries and therefore
execute arbitrary code, gaining the privileges of the PostgreSQL server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered. A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL. A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found. A user could create carefully crafted arrays and cause a denial of
service (crash). The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

The update also fixes some minor problems, notably conflicts with SELinux.

Users of postgresql should update to these erratum packages that contain
patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147380" id="147380">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138020" comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138008" comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138012" comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138022" comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138010" comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138004" comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138016" comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138002" comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138018" comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138014" comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050138006" comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050141" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:141: rh-postgresql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:141-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-141.html" />
          <reference source="CVE" ref_id="CVE-2005-0227" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0227.html" />
          <reference source="CVE" ref_id="CVE-2005-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0244.html" />
          <reference source="CVE" ref_id="CVE-2005-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-0246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0246.html" />
          <reference source="CVE" ref_id="CVE-2005-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0247.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw in the LOAD command in PostgreSQL was discovered.  A local user
could use this flaw to load arbitrary shared librarys and therefore execute
arbitrary code, gaining the privileges of the PostgreSQL server.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0227 to this issue.

A permission checking flaw in PostgreSQL was discovered.  A local user
could bypass the EXECUTE permission check for functions by using the CREATE
AGGREGATE command.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0244 to this issue.

Multiple buffer overflows were found in PL/PgSQL.  A database user who has
permissions to create plpgsql functions could trigger this flaw which could
lead to arbitrary code execution, gaining the privileges of the PostgreSQL
server. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-0245 and CAN-2005-0247 to these issues.

A flaw in the integer aggregator (intagg) contrib module for PostgreSQL was
found.  A user could create carefully crafted arrays and cause a denial of
service (crash).  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0246 to this issue.

Users of PostgreSQL are advised to update to these erratum packages which
are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-14" />
        <updated date="2005-02-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0227.html">CVE-2005-0227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0244.html">CVE-2005-0244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0245.html">CVE-2005-0245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0246.html">CVE-2005-0246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0247.html">CVE-2005-0247</cve>
                <bugzilla href="http://bugzilla.redhat.com/147442" id="147442">CAN-2005-0227 Multiple security issues in PostgreSQL (CAN-2005-0244 CAN-2005-0245 CAN-2005-0246 CAN-2005-0247)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141020" comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141008" comment="rh-postgresql-docs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141010" comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141002" comment="rh-postgresql is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141018" comment="rh-postgresql-python is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141014" comment="rh-postgresql-pl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141012" comment="rh-postgresql-devel is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141022" comment="rh-postgresql-test is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141016" comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141006" comment="rh-postgresql-server is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050141004" comment="rh-postgresql-libs is earlier than 0:7.3.9-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050152" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:152: postfix security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-152.html" />
          <reference source="CVE" ref_id="CVE-2005-0337" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0337.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the ipv6 patch used with Postfix.  When the file
/proc/net/if_inet6 is not available and permit_mx_backup is enabled in
smtpd_recipient_restrictions, this flaw could allow remote attackers to
bypass e-mail restrictions and perform mail relaying by sending mail to an
IPv6 hostname.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0337 to this issue.

These updated packages also fix the following problems:

- wrong permissions on doc directory
- segfault when gethostbyname or gethostbyaddr fails

All users of postfix should upgrade to these updated packages, which
contain patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0337.html">CVE-2005-0337</cve>
                <bugzilla href="http://bugzilla.redhat.com/139983" id="139983">newaliases segfaults when gethostbyname or gethostbyaddr fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146732" id="146732">CAN-2005-0337 open relay bug in postfix ipv6 patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147280" id="147280">Permissions on doc directory is wrong</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152004" comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152005" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050152002" comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050152003" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050165" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:165: rsh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-165.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
    
    <description>The rsh package contains a set of programs that allow users to run
commands on remote machines, login to other machines, and copy files
between machines, using the rsh, rlogin, and rcp commands. All three of
these commands use rhosts-style authentication.

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses rcp to copy files from a malicious server.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0175 to this issue.

These updated packages also address the following bugs:

The rlogind server reported "SIGCHLD set to SIG_IGN but calls wait()"
message to the system log because the original BSD code was ported
incorrectly to linux.

The rexecd server did not function on systems where client hostnames were
not in the DNS service, because server code called gethostbyaddr() for each
new connection.

The rcp command incorrectly used the "errno" variable and produced
erroneous error messages.

The rexecd command ignored settings in the /etc/security/limits file,
because the PAM session was incorrectly initialized.

All users of rsh should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
                <bugzilla href="http://bugzilla.redhat.com/146978" id="146978">RHEL4: rexecd does not set limits on /etc/security/limits</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146979" id="146979">RHEL4: rcp gives incorrect error report when file system writes fai</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165002" comment="rsh is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074003" comment="rsh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050165004" comment="rsh-server is earlier than 0:0.17-25.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050074005" comment="rsh-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050173" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:173: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:173-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-173.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles FQDN lookups.  It was possible  
to crash the Squid server by sending a carefully crafted DNS response to  
an FQDN lookup.  The Common Vulnerabilities and Exposures project  
(cve.mitre.org) has assigned the name CAN-2005-0446 to this issue.  
  
Users of squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050173002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050175" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:175: kdenetwork security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:175-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-175.html" />
          <reference source="CVE" ref_id="CVE-2005-0205" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0205.html" />
    
    <description>The kdenetwork packages contain a collection of networking applications for
the K Desktop Environment.

A bug was found in the way kppp handles privileged file descriptors.  A
malicious local user could make use of this flaw to modify the /etc/hosts
or /etc/resolv.conf files, which could be used to spoof domain information. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0205 to this issue.

Please note that the default installation of kppp on Red Hat Enterprise
Linux uses consolehelper and is not vulnerable to this issue.  However, the
kppp FAQ provides instructions for removing consolehelper and running kppp
suid root, which is a vulnerable configuration.

Users of kdenetwork should upgrade to these updated packages, which contain
a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0205.html">CVE-2005-0205</cve>
                <bugzilla href="http://bugzilla.redhat.com/148912" id="148912">CAN-2005-0205 kppp local domain name hijacking</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175002" comment="kdenetwork is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050175004" comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050176" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:176: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-176.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0589.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0592.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the Firefox string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

A bug was found in the way Firefox handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Firefox allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527).

A flaw was found in the way Firefox displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Firefox handles plug-in temporary files. A
malicious local user could create a symlink to a victims directory, causing
it to be deleted when the victim exits Firefox. (CAN-2005-0578)

A bug has been found in one of Firefox's UTF-8 converters. It may be
possible for an attacker to supply a specially crafted UTF-8 string to the
buggy converter, leading to arbitrary code execution. (CAN-2005-0592)

A bug was found in the Firefox javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Firefox displays the HTTP authentication prompt.
When a user is prompted for authentication, the dialog window is displayed
over the active tab, regardless of the tab that caused the pop-up to appear
and could trick a user into entering their username and password for a
trusted site.  (CAN-2005-0584)

A bug was found in the way Firefox displays the save file dialog. It is
possible for a malicious webserver to spoof the Content-Disposition header,
tricking the user into thinking they are downloading a different filetype.
(CAN-2005-0586)

A bug was found in the way Firefox handles users "down-arrow" through auto
completed choices. When an autocomplete choice is selected, the information
is copied into the input control, possibly allowing a malicious web site to
steal information by tricking a user into arrowing through autocompletion
choices. (CAN-2005-0589)

Several bugs were found in the way Firefox displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0593)

A bug was found in the way Firefox displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

A bug was found in the way Firefox handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

A bug was found in the way Firefox displays the installation confirmation
dialog. An attacker could add a long user:pass before the true hostname,
tricking a user into thinking they were installing content from a trusted
source. (CAN-2005-0590)

A bug was found in the way Firefox displays download and security dialogs.
An attacker could cover up part of a dialog window tricking the user into
clicking "Allow" or "Open", which could potentially lead to arbitrary code
execution. (CAN-2005-0591)

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-01" />
        <updated date="2005-03-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0589.html">CVE-2005-0589</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0592.html">CVE-2005-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/142506" id="142506">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144216" id="144216">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147402" id="147402">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147727" id="147727">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147735" id="147735">CAN-2005-0231 firefox javascript tab security bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149876" id="149876">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149923" id="149923">CAN-2005-0578 Unsafe /tmp/plugtmp directory exploitable to erase user's files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149929" id="149929">CAN-2005-0584 HTTP auth prompt tab spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149930" id="149930">CAN-2005-0586 Download dialog spoofing using Content-Disposition header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149931" id="149931">CAN-2005-0588 XSLT can include stylesheets from arbitrary hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149934" id="149934">CAN-2005-0589 Autocomplete data leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149936" id="149936">CAN-2005-0590 Install source spoofing with user:pass@host</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149937" id="149937">CAN-2005-0591 Spoofing download and security dialogs with overlapping windows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149938" id="149938">CAN-2005-0592 Heap overflow possible in UTF8 to Unicode conversion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149939" id="149939">CAN-2005-0593 SSL "secure site" indicator spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176002" comment="firefox is earlier than 0:1.0.1-1.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050198" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:198: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:198-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-198.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>X.Org X11 is the X Window System which provides the core functionality
of the Linux GUI desktop.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
carefully crafted XPM file in such a way that it could cause an application
linked with libXpm to execute arbitrary code when the file was opened by a
victim. The Common Vulnerabilities and Exposures project  (cve.mitre.org)
has assigned the name CAN-2005-0605 to this issue. 

Since the initial release of Red Hat Enterprise Linux 4, a number of issues
have been addressed in the X.Org X11 X Window System.  This erratum also
updates X11R6.8 to the latest stable point release (6.8.2), which includes
various stability and reliability fixes including (but not limited to) the
following:

- The 'radeon' driver has been modified to disable "RENDER" acceleration
  by default, due to a bug in the implementation which has not yet
  been isolated.  This can be manually re-enabled by using the
  following option in the device section of the X server config file:

    Option "RenderAccel"

- The 'vmware' video driver is now available on 64-bit AMD64 and
  compatible systems.

- The Intel 'i810' video driver is now available on 64-bit EM64T
  systems.

- Stability fixes in the X Server's PCI handling layer for 64-bit systems,
  which resolve some issues reported by "vesa" and "nv" driver users.

- Support for Hewlett Packard's Itanium ZX2 chipset.

- Nvidia "nv" video driver update provides support for some of
  the newer Nvidia chipsets, as well as many stability and reliability
  fixes.

- Intel i810 video driver stability update, which fixes the widely
  reported i810/i815 screen refresh issues many have experienced.

- Packaging fixes for multilib systems, which permit both 32-bit
  and 64-bit X11 development environments to be simultaneously installed
  without file conflicts.

In addition to the above highlights, the X.Org X11 6.8.2 release has a
large number of additional stability fixes which resolve various other
issues reported since the initial release of Red Hat Enterprise Linux 4. 

All users of X11 should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-06-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/136941" id="136941">font corruption on openoffice.org menus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143910" id="143910">X is unusable on GeForce 6600GT with nForce4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150036" id="150036">CAN-2005-0605 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157962" id="157962">xorg-x11-6.8.1-23 missing half of Lucida fonts</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198024" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198022" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198030" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198034" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198032" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198028" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198062" comment="fonts-xorg-ISO8859-15-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198063" comment="fonts-xorg-ISO8859-15-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198042" comment="fonts-xorg-truetype is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198043" comment="fonts-xorg-truetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198040" comment="fonts-xorg-base is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198041" comment="fonts-xorg-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198052" comment="fonts-xorg-ISO8859-2-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198053" comment="fonts-xorg-ISO8859-2-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198060" comment="fonts-xorg-ISO8859-14-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198061" comment="fonts-xorg-ISO8859-14-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198054" comment="fonts-xorg-ISO8859-9-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198055" comment="fonts-xorg-ISO8859-9-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198044" comment="fonts-xorg-syriac is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198045" comment="fonts-xorg-syriac is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198064" comment="fonts-xorg-ISO8859-15-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198065" comment="fonts-xorg-ISO8859-15-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198046" comment="fonts-xorg-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198047" comment="fonts-xorg-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198050" comment="fonts-xorg-ISO8859-2-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198051" comment="fonts-xorg-ISO8859-2-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198048" comment="fonts-xorg-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198049" comment="fonts-xorg-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198066" comment="fonts-xorg-cyrillic is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198067" comment="fonts-xorg-cyrillic is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198058" comment="fonts-xorg-ISO8859-14-75dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198059" comment="fonts-xorg-ISO8859-14-75dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198056" comment="fonts-xorg-ISO8859-9-100dpi is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198057" comment="fonts-xorg-ISO8859-9-100dpi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050198038" comment="fonts-xorg is earlier than 0:6.8.1.1-1.EL.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198039" comment="fonts-xorg is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050201" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:201: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:201-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-201.html" />
          <reference source="CVE" ref_id="CVE-2005-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0446.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
  
A bug was found in the way Squid handles fully qualified domain name (FQDN)
lookups.  A malicious DNS server could crash Squid by sending a carefully
crafted DNS response to an FQDN lookup.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0446 to
this issue.  
 
This erratum also includes two minor patches to the LDAP helpers.  One 
corrects a slight malformation in ldap search requests (although all 
known LDAP servers accept the requests).  The other adds documentation 
for the -v option to the ldap helpers. 
 
Users of Squid should upgrade to this updated package, which contains a  
backported patch, and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0446.html">CVE-2005-0446</cve>
                <bugzilla href="http://bugzilla.redhat.com/148882" id="148882">CAN-2005-0446 Squid DoS from bad DNS response</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050201002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050213" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:213: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:213-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-213.html" />
          <reference source="CVE" ref_id="CVE-2005-0206" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0206.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). RHSA-2004:592 contained a fix for this issue, but it was
found to be incomplete and left 64-bit architectures vulnerable. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0206 to this issue.

All users of xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0206.html">CVE-2005-0206</cve>
                <bugzilla href="http://bugzilla.redhat.com/135393" id="135393">CAN-2004-0888 xpdf integer overflows (CAN-2005-0206)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050213002" comment="xpdf is earlier than 1:2.02-9.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050215" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:215: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:215-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-215.html" />
          <reference source="CVE" ref_id="CVE-2005-0208" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0208.html" />
          <reference source="CVE" ref_id="CVE-2005-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0472.html" />
          <reference source="CVE" ref_id="CVE-2005-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0473.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

Two HTML parsing bugs were discovered in Gaim. It is possible that a remote
attacker could send a specially crafted message to a Gaim client, causing
it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0208 and CAN-2005-0473 to
these issues.

A bug in the way Gaim processes SNAC packets was discovered.  It is
possible that a remote attacker could send a specially crafted SNAC packet
to a Gaim client, causing the client to stop responding.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0472 to this issue.

Additionally, various client crashes, memory leaks, and protocol issues
have been resolved.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.1.4 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-10" />
        <updated date="2005-03-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0208.html">CVE-2005-0208</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0472.html">CVE-2005-0472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0473.html">CVE-2005-0473</cve>
                <bugzilla href="http://bugzilla.redhat.com/149273" id="149273">CAN-2005-0472 Gaim DoS issues (CAN-2005-0473)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149533" id="149533">CAN-2005-0208 Gaim HTML parsing DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215002" comment="gaim is earlier than 1:1.1.4-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215005" comment="gaim is earlier than 1:1.1.4-1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050232" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:232: ipsec-tools security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:232-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-232.html" />
          <reference source="CVE" ref_id="CVE-2005-0398" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0398.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel. The ipsec-tools package includes:

- setkey, a program to directly manipulate policies and SAs
- racoon, an IKEv1 keying daemon

A bug was found in the way the racoon daemon handled incoming ISAKMP
requests.  It is possible that an attacker could crash the racoon daemon by
sending a specially crafted ISAKMP packet.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0398 to
this issue. 

Additionally, the following issues have been fixed:
- racoon mishandled restarts in the presence of stale administration sockets.
- on Red Hat Enterprise Linux 4, racoon and setkey did not properly set up
  forward policies, which prevented tunnels from working.

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0398.html">CVE-2005-0398</cve>
                <bugzilla href="http://bugzilla.redhat.com/145531" id="145531">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145535" id="145535">CAN-2005-0398 racoon DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148950" id="148950">racoon unable to start with stale socket /tmp/.racoon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150179" id="150179">ipsec/racoon/setkey does not properly forward packets to vpn peer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232002" comment="ipsec-tools is earlier than 0:0.2.5-0.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232005" comment="ipsec-tools is earlier than 0:0.3.3-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050232003" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050235" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:235: mailman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:235-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-235.html" />
          <reference source="CVE" ref_id="CVE-2004-1177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1177.html" />
    
    <description>Mailman manages electronic mail discussion and e-newsletter lists. 

A cross-site scripting (XSS) flaw in the driver script of mailman prior to
version 2.1.5 could allow remote attackers to execute scripts as other web
users. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2004-1177 to this issue.

Users of mailman should update to this erratum package, which corrects this
issue by turning on STEALTH_MODE by default and using Utils.websafe() to
quote the html.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1177.html">CVE-2004-1177</cve>
                <bugzilla href="http://bugzilla.redhat.com/132750" id="132750">Mailman doesn't work with courier</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142605" id="142605">init script doesn't use /var/lock/subsys</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143008" id="143008">mailman logrotate has wrong location for mailmanctl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147833" id="147833">CAN-2004-1177 - mailman</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235002" comment="mailman is earlier than 3:2.1.5-25.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050235005" comment="mailman is earlier than 3:2.1.5-33.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050136003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050238" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:238: evolution security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-238.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools. Evolution includes a mailer, calendar, contact manager, and
communication facility.  The tools which make up Evolution are tightly
integrated with one another and act as a seamless personal information
management tool.

A bug was found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue. On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default. Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

Additionally, these updated packages address the following issues:

-- If evolution ran during a GNOME session, the evolution-wombat process 
   did not exit when the user logged out of the desktop.

-- For folders marked for Offline Synchronization: if a user moved a
   message from a Local Folder to an IMAP folder while in
   Offline mode, the message was not present in either folder after
   returning to Online mode.
 
   This update fixes this problem. Email messages that have been lost 
   this way may still be present in the following path: 

   ~/evolution/&amp;lt;NAME_OF_MAIL_STORE&amp;gt;/ \
   &amp;lt;path-to-folder-via-subfolder-directories&amp;gt;/ \
   &amp;lt;temporary-uid-of-message&amp;gt;

If this bug has affected you it may be possible to recover data by
examining the contents of this directory.

All users of evolution should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
                <bugzilla href="http://bugzilla.redhat.com/125528" id="125528">Moving to IMAP folder while offline eats mail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155376" id="155376">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157352" id="157352">.ics import crashes Evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157354" id="157354">Creating a meeting crashes evolution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157355" id="157355">Cannot create all day event in calendar</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238002" comment="evolution is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050238004" comment="evolution-devel is earlier than 0:1.4.5-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050256" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:256: glibc security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-256.html" />
          <reference source="CVE" ref_id="CVE-2004-1453" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1453.html" />
    
    <description>The GNU libc packages (known as glibc) contain the standard C libraries
used by applications.

It was discovered that the use of LD_DEBUG, LD_SHOW_AUXV, and
LD_DYNAMIC_WEAK were not restricted for a setuid program. A local user
could utilize this flaw to gain information, such as the list of symbols
used by the program. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1453 to this issue.

This erratum addresses the following bugs in the GNU C Library:

- fix stack alignment in IA-32 clone
- fix double free in globfree
- fix fnmatch to avoid jumping based on unitialized memory read
- fix fseekpos after ungetc
- fix TZ env var handling if the variable ends with + or -
- avoid depending on values read from unitialized memory in strtold
  on certain architectures
- fix mapping alignment computation in dl-load
- fix i486+ strncat inline assembly
- make gethostid/sethostid work on bi-arch platforms
- fix ppc64 getcontext/swapcontext
- fix pthread_exit if called after pthread_create, but before the created
  thread actually started
- fix return values for tgamma (+-0)
- fix handling of very long lines in /etc/hosts
- avoid page aliasing of thread stacks on AMD64
- avoid busy loop in malloc if concurrent with fork
- allow putenv and setenv in shared library constructors
- fix restoring of CCR in swapcontext and getcontext on ppc64
- avoid using sigaction (SIGPIPE, ...) in syslog implementation

All users of glibc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1453.html">CVE-2004-1453</cve>
                <bugzilla href="http://bugzilla.redhat.com/135125" id="135125">telnet: 0: Name or service not known</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138439" id="138439">re_compile_pattern segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140378" id="140378">[RHEL3] glibc behavior with long lines in /etc/hosts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142617" id="142617">[RHEL3] libc's getXXent and getXXbyYY are inefficient for large groups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143279" id="143279">x86_64 ecvt() returns "inf" for valid denormalized doubles</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146210" id="146210">zdump -v GMT segfaults in x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146402" id="146402">CAN-2004-1453 Information leak with LD_DEBUG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146710" id="146710">pthread_getspecific gets non-NULL value for new key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147478" id="147478">nscd fails with big group in ldap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149205" id="149205">malloc: top chunk is corrupt w/ MALLOC_CHECK_=3</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256012" comment="glibc-common is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256013" comment="glibc-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256006" comment="glibc-headers is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256007" comment="glibc-headers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256008" comment="nptl-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256009" comment="nptl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256004" comment="glibc-devel is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256005" comment="glibc-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256016" comment="glibc-debug is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256017" comment="glibc-debug is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256010" comment="glibc-profile is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256011" comment="glibc-profile is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256002" comment="glibc is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256003" comment="glibc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256014" comment="nscd is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256015" comment="nscd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050256018" comment="glibc-utils is earlier than 0:2.3.2-95.33" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050256019" comment="glibc-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050267" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:267: Evolution security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-267.html" />
          <reference source="CVE" ref_id="CVE-2005-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2549.html" />
          <reference source="CVE" ref_id="CVE-2005-2550" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2550.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in Evolution.  If a user tries to save a
carefully crafted meeting or appointment, arbitrary code may be executed as
the user running Evolution. The Common Vulnerabilities and Exposures
project has assigned the name CAN-2005-2550 to this issue.

Additionally, several other format string bugs were found in Evolution. If
a user views a malicious vCard, connects to a malicious LDAP server, or
displays a task list from a malicious remote server, arbitrary code may be
executed as the user running Evolution. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2005-2549 to this issue. Please
note that this issue only affects Red Hat Enterprise Linux 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-29" />
        <updated date="2005-08-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2549.html">CVE-2005-2549</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2550.html">CVE-2005-2550</cve>
                <bugzilla href="http://bugzilla.redhat.com/165235" id="165235">CAN-2005-2549 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL4) (CAN-2005-2550)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165236" id="165236">CAN-2005-2550 Sitic Vulnerability Advisory: SA05-001 Evolution multiple remote format string bugs (RHEL3)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267002" comment="evolution is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267004" comment="evolution-devel is earlier than 0:1.4.5-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267007" comment="evolution is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050267008" comment="evolution-devel is earlier than 0:2.0.2-16.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050271" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:271: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:271-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-271.html" />
          <reference source="CVE" ref_id="CVE-2005-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0455.html" />
          <reference source="CVE" ref_id="CVE-2005-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0611.html" />
    
    <description>HelixPlayer is a media player.

A stack based buffer overflow bug was found in HelixPlayer's Synchronized
Multimedia Integration Language (SMIL) file processor. An attacker could
create a specially crafted SMIL file which would execute arbitrary code
when opened by a user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0455 to this issue.

A buffer overflow bug was found in the way HelixPlayer decodes WAV files.
An attacker could create a specially crafted WAV file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0611 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer 1.0.3 which is not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-03" />
        <updated date="2005-03-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0455.html">CVE-2005-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0611.html">CVE-2005-0611</cve>
                <bugzilla href="http://bugzilla.redhat.com/150098" id="150098">CAN-2005-0455 buffer overflow in helixplayer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150103" id="150103">CAN-2005-0611 .wav overflow in helixplayer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271002" comment="HelixPlayer is earlier than 1:1.0.3-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050277" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:277: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:277-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-277.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the Mozilla string handling functions. If a malicious
website is able to exhaust a system's memory, it becomes possible to
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Please note that other security issues have been found that affect Mozilla.
These other issues have a lower severity, and are therefore planned to be
released as additional security updates in the future.

Users of Mozilla should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-04" />
        <updated date="2005-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/150124" id="150124">CAN-2005-0255 Memory overwrite in string library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277010" comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277012" comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277004" comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277020" comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277002" comment="mozilla is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277016" comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277014" comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277008" comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277006" comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050277018" comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050293" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:293: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:293-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-293.html" />
          <reference source="CVE" ref_id="CVE-2004-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0075.html" />
          <reference source="CVE" ref_id="CVE-2004-0177" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0177.html" />
          <reference source="CVE" ref_id="CVE-2004-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0814.html" />
          <reference source="CVE" ref_id="CVE-2004-1058" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1058.html" />
          <reference source="CVE" ref_id="CVE-2004-1073" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1073.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0137" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0137.html" />
          <reference source="CVE" ref_id="CVE-2005-0204" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0204.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0403.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
    
    <description>The following security issues were fixed:

The Vicam USB driver did not use the copy_from_user function to access
userspace, crossing security boundaries. (CAN-2004-0075)

The ext3 and jfs code did not properly initialize journal descriptor
blocks.  A privileged local user could read portions of kernel memory.
(CAN-2004-0177)

The terminal layer did not properly lock line discipline changes or pending
IO.  An unprivileged local user could read portions of kernel memory, or
cause a denial of service (system crash). (CAN-2004-0814)

A race condition was discovered.  Local users could use this flaw to read
the environment variables of another process that is still spawning via
/proc/.../cmdline. (CAN-2004-1058)

A flaw in the execve() syscall handling was discovered, allowing a local
user to read setuid ELF binaries that should otherwise be protected by
standard permissions. (CAN-2004-1073).  Red Hat originally reported this
as being fixed by RHSA-2004:549, but the associated fix was missing from
that update.

Keith Owens reported a flaw in the Itanium unw_unwind_to_user() function.
A local user could use this flaw to cause a denial of service (system
crash) on the Itanium architecture. (CAN-2005-0135)

A missing Itanium syscall table entry could allow an unprivileged
local user to cause a denial of service (system crash) on the Itanium
architecture. (CAN-2005-0137)

A flaw affecting the OUTS instruction on the AMD64 and Intel EM64T
architectures was discovered.  A local user could use this flaw to
access privileged IO ports. (CAN-2005-0204)

A flaw was discovered in the Linux PPP driver.  On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 was
discovered that left a pointer to a freed tty structure.  A local user
could potentially use this flaw to cause a denial of service (system crash)
or possibly gain read or write access to ttys that should normally be
prevented. (CAN-2005-0403)

A flaw in fragment queuing was discovered affecting the netfilter
subsystem.  On systems configured to filter or process network packets (for
example those configured to do firewalling), a remote attacker could send a
carefully crafted set of fragmented packets to a machine and cause a denial
of service (system crash).  In order to sucessfully exploit this flaw, the
attacker would need to know (or guess) some aspects of the firewall ruleset
in place on the target system to be able to craft the right fragmented
packets. (CAN-2005-0449)

Missing validation of an epoll_wait() system call parameter could allow
a local user to cause a denial of service (system crash) on the IBM S/390
and zSeries architectures. (CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered.  A local
user could potentially use this flaw to cause a denial of service (system
crash). (CAN-2005-0749)

A flaw was discovered in the bluetooth driver system.  On system where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

In addition to the security issues listed above, there was an important
fix made to the handling of the msync() system call for a particular case
in which the call could return without queuing modified mmap()'ed data for
file system update. (BZ 147969)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

Red Hat Enterprise Linux 3 users are advised to upgrade their kernels to
the packages associated with their machine architectures/configurations

Please note that the fix for CAN-2005-0449 required changing the
external symbol linkages (kernel module ABI) for the ip_defrag()
and ip_ct_gather_frags() functions.  Any third-party module using either
of these would also need to be fixed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-22" />
        <updated date="2005-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0075.html">CVE-2004-0075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0177.html">CVE-2004-0177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0814.html">CVE-2004-0814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1058.html">CVE-2004-1058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1073.html">CVE-2004-1073</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0137.html">CVE-2005-0137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0204.html">CVE-2005-0204</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0403.html">CVE-2005-0403</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
                <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293004" comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293002" comment="kernel is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293006" comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293016" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293018" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050293014" comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050294" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:294: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 5 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:294-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-294.html" />
          <reference source="CVE" ref_id="CVE-2005-0757" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0757.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the fifth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - support for 2-TB partitions on block devices
  - support for new disk, network, and USB devices
  - support for clustered APIC mode on AMD64 NUMA systems
  - netdump support on AMD64, Intel EM64T, Itanium, and ppc64 systems
  - diskdump support on sym53c8xx and SATA piix/promise adapters
  - NMI switch support on AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 3.

Some key areas affected by these fixes include the kernel's networking,
SATA, TTY, and USB subsystems, as well as the architecture-dependent
handling under the ia64, ppc64, and x86_64 directories.  Scalability
improvements were made primarily in the memory management and file
system areas.

A flaw in offset handling in the xattr file system code backported to
Red Hat Enterprise Linux 3 was fixed.  On 64-bit systems, a user who
can access an ext3 extended-attribute-enabled file system could cause
a denial of service (system crash).  This issue is rated as having a
moderate security impact (CAN-2005-0757).

The following device drivers have been upgraded to new versions:

  3c59x ------ LK1.1.18
  3w-9xxx ---- 2.24.00.011fw (new in Update 5)
  3w-xxxx ---- 1.02.00.037
  8139too ---- (upstream 2.4.29)
  b44 -------- 0.95
  cciss ------ v2.4.54.RH1
  e100 ------- 3.3.6-k2
  e1000 ------ 5.6.10.1-k2
  lpfcdfc ---- 1.0.13 (new in Update 5)
  tg3 -------- 3.22RH

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-18" />
        <updated date="2005-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0757.html">CVE-2005-0757</cve>
                <bugzilla href="http://bugzilla.redhat.com/116289" id="116289">BLKPG_ADD_PARTITION op of BLKPG ioctl doesn't let you add partitions >= 1TB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119351" id="119351">Getting OOM errors on an unconstrained system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121032" id="121032">CAN-2004-0177 ext3 infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121716" id="121716">Raw device I/O transfer size limited to 32KB.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123415" id="123415">API Breakage: NFS "No locks available" with kernel 2.4.21-15.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/124600" id="124600">Unexpected error: VFS: Busy inodes after unmount. Self-destruct in 5 seconds.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/126407" id="126407">CAN-2004-0075 Vicam USB user/kernel copying</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/127066" id="127066">Panic is occurring in the I/O completion interrupt handling for the character interface driver (sg).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128176" id="128176">Add the 3w-9xxx module (required for the 9000 series 3ware cards)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129084" id="129084">ICH6 SATA support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130113" id="130113">Strange output of /proc/mtrr</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130365" id="130365">Request to include EMC Celerra and iSCSI devices to the black list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130774" id="130774">oops in drivers/char/tty_io.c:init_dev()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131674" id="131674">CAN-2004-0814 potential race condition in RHEL 2.1/3 tty layer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131981" id="131981">O_DIRECT doesn't work on LVM devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132162" id="132162">NFS intr flag prevents core dumps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132257" id="132257">LTC-8859: softdog.o need to be included into RHEL distributions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132339" id="132339">x86 compatibility mode apps using signals crash under EM64T</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132494" id="132494">POSIX Asynchronous IO support is unstable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132838" id="132838">Kernel Panic: Unable to satisfy kernel paging request... when starting ServerVantage.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133020" id="133020">[RHEL3][IA32E][X86_64]Wrong FPU IP and DP in the SIGFPE signal context</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133108" id="133108">CAN-2004-0814 input/serio local DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133113" id="133113">CAN-2004-1058 /proc/&lt;PID>/cmdline information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133388" id="133388">3c59x: eth0: Transmit error, Tx status register d0. (10Mb hub)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/133905" id="133905">kernel crash, fatal exception, accessing /proc, EXT3-fs error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134832" id="134832">Ia32e + Intel SATA 82801EB + kernel 2.4.21-20EL;   unable to mount root partition.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135266" id="135266">Panics while backing up LVM snapshots</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135583" id="135583">RHEL3U3 panics on boot for HP rx5670</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135688" id="135688">NFS ESTALES returned on open [IT50092]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136317" id="136317">When copying rootfs to /mnt/sdc/, rsync accessed /proc/kcore and kernel crashed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136398" id="136398">NFS direct reads don't flush dirty cached pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137201" id="137201">RHEL3U2/U3 x86-64 - /proc/mtrr reported incorrectly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137519" id="137519">ps shows bad PPID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137830" id="137830">worktodo does not support NFS aio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137961" id="137961">tg3 fiber auto-negotiation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138182" id="138182">Kernel hang when cat'ting file on intr NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138240" id="138240">MCA in tulip on ifconfig down/reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138815" id="138815">[RHEL3-U5][Diskdump] Stalls before printing "CPU frozen"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138827" id="138827">usb: raced timeout errors when using usb/serial adapter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138905" id="138905">Unkillable processes under 64bit Linux which use Kernel Asynchronous I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139421" id="139421">[RHEL3-U4][Diskdump] Diskdump failed with serial console enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139434" id="139434">[RHEL3-U4][Diskdump] Segmentation Fault after cliloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139440" id="139440">[RHEL3-U5][Diskdump] All CPUs are displayed in CPU frozen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139465" id="139465">em64t/ia32e kernel panic: 'interrupt handler - not syncing' during heavy network I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140083" id="140083">lx-choptp19 crashed running 2.4.21-20.EL.BZ131027.hotfixhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140331" id="140331">stack overflows can occur on x86_64 under stack pressure when softirq's are handled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140552" id="140552">Kernel wrongly complains about application bug when loading modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140585" id="140585">[RHEL3][PATCH] SIOCGHWADDR does not clear buffer for ppp connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140616" id="140616">RHEL3 PATCH dev.c: clear SIOCGIFHWADDR buffer if !dev->addr_len</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140790" id="140790">e100 and e1000 drivers should return EINVAL when ethtool tries to set rx-mini or rx-jumbo</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141282" id="141282">nptl futex_wait fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141377" id="141377">[PATCH] memory leak in ipv6   ip6_{push,flush}_pending_frames()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141388" id="141388">FAT32 file system zero length files corruption after remount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141697" id="141697">ATAPI-CDROM not accessible with kernel options ide-scsi and swiotlb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141757" id="141757">Infinite loop when syncing over automounted NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142683" id="142683">bonding with mii monitoring does not work with realtek card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142725" id="142725">[PATCH] video1394 fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142954" id="142954">sata_sx4 4GB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143542" id="143542">Unable to handle kernel NULL pointer dereference at virtual address 00000004</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143565" id="143565">NIC BCM4401 on Dell Inspiron 5100 broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143625" id="143625">kernel can not register scsi LUNs above 7 for mylexFFx2 FC RAID controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144059" id="144059">CAN-2005-0403 panic in tty init_dev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144260" id="144260">U4 kernel sound broken on certain AC 97 systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144360" id="144360">Fibre Channel tape speed regression (qla2200)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144530" id="144530">random poolsize sysctl handler integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144990" id="144990">Anaconda installer partion error large RAID volume</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145331" id="145331">kernel panic in get_signal_to_deliver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145409" id="145409">panic_on_oops hook removed on ia64 by diskdump patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145563" id="145563">tar crashes DELL server every 4th day.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145746" id="145746">mmap() system call can return Nil</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146345" id="146345">recv returns EAGAIN instead of EINTR when interrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146501" id="146501">ext2/ext3 w/ 1024 blocksize eats all memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147541" id="147541">rsync creating truncated files on fat32 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147580" id="147580">Race condition in md subsystem causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147704" id="147704">laus incorrectly truncates path string when predicate filter is used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147969" id="147969">msync(..., ..., MS_SYNC) returning before data written to disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148855" id="148855">CAN-2005-0204 OUTS instruction does not cause SIGSEGV for all ports</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148869" id="148869">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150334" id="150334">Kernel panic:  Code: Bad EIP value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151086" id="151086">kernel locks up tty/psuedo-tty access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151241" id="151241">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151805" id="151805">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151934" id="151934">Running lshw causes MCA on Olympia rx8620</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152178" id="152178">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152411" id="152411">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152552" id="152552">CAN-2004-1073 looks unfixed in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152627" id="152627">sata_sil missing PCI IDs for ATI SATA controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152959" id="152959">Repeated Kernel Panics while using LVM Snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155234" id="155234">CAN-2005-0137 ia64 syscall_table DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156617" id="156617">SIGCHLD set to SIG_IGN but calls wait().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156882" id="156882">aggressively clean bhs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156928" id="156928">sata_promise in 2.4.21-27.0.4.EL doesn't support Promise sataII 150 tx4 yet</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294006" comment="kernel-source is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294002" comment="kernel is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294008" comment="kernel-doc is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294018" comment="kernel-hugemem is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294014" comment="kernel-BOOT is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294004" comment="kernel-unsupported is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050294012" comment="kernel-smp is earlier than 0:2.4.21-32.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050300" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:300: libexif security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:300-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-300.html" />
          <reference source="CVE" ref_id="CVE-2005-0664" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0664.html" />
    
    <description>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

A bug was found in the way libexif parses EXIF tags. An attacker could
create a carefully crafted EXIF image file which could cause image viewers
linked against libexif to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0664 to this issue.

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-21" />
        <updated date="2005-03-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0664.html">CVE-2005-0664</cve>
                <bugzilla href="http://bugzilla.redhat.com/150503" id="150503">CAN-2005-0664 buffer overflow in libexif</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300004" comment="libexif-devel is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300005" comment="libexif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050300002" comment="libexif is earlier than 0:0.5.12-5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050300003" comment="libexif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050306" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:306: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:306-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-306.html" />
          <reference source="CVE" ref_id="CVE-2005-0699" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0699.html" />
          <reference source="CVE" ref_id="CVE-2005-0704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0704.html" />
          <reference source="CVE" ref_id="CVE-2005-0705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0705.html" />
          <reference source="CVE" ref_id="CVE-2005-0739" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0739.html" />
          <reference source="CVE" ref_id="CVE-2005-0765" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0765.html" />
          <reference source="CVE" ref_id="CVE-2005-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0766.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.


A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.

A buffer overflow flaw was discovered in the Etheric dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0704 to this issue.

The GPRS-LLC dissector could crash if the "ignore cipher bit" option was
set. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0705 to this issue.

A buffer overflow flaw was discovered in the 3GPP2 A11 dissector.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0699 to this issue.

A buffer overflow flaw was discovered in the IAPP dissector.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0739 to this issue.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-18" />
        <updated date="2005-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0699.html">CVE-2005-0699</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0704.html">CVE-2005-0704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0705.html">CVE-2005-0705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0739.html">CVE-2005-0739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0765.html">CVE-2005-0765</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0766.html">CVE-2005-0766</cve>
                <bugzilla href="http://bugzilla.redhat.com/150705" id="150705">CAN-2005-0699 Multiple ethereal issues (CAN-2005-0704 CAN-2005-0705)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306004" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306002" comment="ethereal is earlier than 0:0.10.10-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306008" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050306007" comment="ethereal is earlier than 0:0.10.10-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050307" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:307: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:307-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-307.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

Users of KDE should upgrade to these erratum packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-06" />
        <updated date="2005-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/151373" id="151373">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307002" comment="kdelibs is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050307004" comment="kdelibs-devel is earlier than 6:3.1.3-6.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050320" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:320: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:320-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-320.html" />
          <reference source="CVE" ref_id="CVE-2005-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0397.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

Additionally, a bug was fixed which caused ImageMagick(TM) to occasionally
segfault when writing TIFF images to standard output.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0397.html">CVE-2005-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/142045" id="142045">Segmentation fault on conversion to TIFF (possible libtiff bug)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150185" id="150185">CAN-2005-0397 ImageMagick format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320010" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320004" comment="ImageMagick-devel is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320006" comment="ImageMagick-perl is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320002" comment="ImageMagick is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050320008" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050323" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:323: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:323-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-323.html" />
          <reference source="CVE" ref_id="CVE-2004-0906" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0906.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2004-1613" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1613.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0147.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1380 to this issue.

A bug was found in the way Mozilla allowed plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0232 to this issue.

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0149 to
this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0147 to this issue.

A bug was found in the way Mozilla handles certain start tags followed by a
NULL character.  A malicious web page could cause Mozilla to crash when
viewed by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1613 to this issue.

A bug was found in the way Mozilla sets file permissions when installing
XPI packages.  It is possible for an XPI package to install some files
world readable or writable, allowing a malicious local user to steal
information or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-0906 to
this issue.

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0141 to this issue.

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0144 to this issue.

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.4.4 and additional backported patches to correct
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0906.html">CVE-2004-0906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1613.html">CVE-2004-1613</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0147.html">CVE-2005-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
                <bugzilla href="http://bugzilla.redhat.com/145597" id="145597">CAN-2005-0141 Link opened in new tab can load a local file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145609" id="145609">CAN-2005-0144 Secure site lock can be spoofed with view-source:</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145610" id="145610">CAN-2004-1380 Input stealing from other tabs (CAN-2004-1381)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145614" id="145614">CAN-2005-0147 Browser responds to proxy auth request from non-proxy server (ssl/https)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145615" id="145615">CAN-2005-0149 Mail responds to cookie requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151209" id="151209">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151492" id="151492">CAN-2004-1613 Mozilla start tag NULL character DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151494" id="151494">CAN-2004-0906 Mozilla XPI installer insecure file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151496" id="151496">CAN-2005-0232 fireflashing vulnerability (CAN-2005-0527)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323018" comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323014" comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323016" comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323010" comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323002" comment="mozilla is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323020" comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323006" comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323004" comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323012" comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050323008" comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050325" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:325: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-325.html" />
          <reference source="CVE" ref_id="CVE-2005-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0237.html" />
          <reference source="CVE" ref_id="CVE-2005-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0365.html" />
          <reference source="CVE" ref_id="CVE-2005-0396" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0396.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment.

The International Domain Name (IDN) support in the Konqueror browser
allowed remote attackers to spoof domain names using punycode encoded
domain names.  Such domain names are decoded in URLs and SSL certificates
in a way that uses homograph characters from other character sets, which
facilitates phishing attacks. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0237 to this issue.

Sebastian Krahmer discovered a flaw in dcopserver, the KDE Desktop
Communication Protocol (DCOP) daemon.  A local user could use this flaw to
stall the DCOP authentication process, affecting any local desktop users
and causing a reduction in their desktop functionality.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0396 to this issue.

A flaw in the dcopidlng script was discovered. The dcopidlng script would
create temporary files with predictable filenames which could allow local
users to overwrite arbitrary files via a symlink attack. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0365 to this issue.

Users of KDE should upgrade to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0237.html">CVE-2005-0237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0365.html">CVE-2005-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0396.html">CVE-2005-0396</cve>
                <bugzilla href="http://bugzilla.redhat.com/147405" id="147405">CAN-2005-0237 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148822" id="148822">CAN-2005-0365 dcopidlng insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150090" id="150090">CAN-2005-0396 kdelibs DCOP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325002" comment="kdelibs is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050325004" comment="kdelibs-devel is earlier than 6:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050327" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:327: telnet security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-327.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>The telnet package provides a command line telnet client. The telnet-server
package includes a telnet daemon, telnetd, that supports remote login to
the host machine.

Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468
and CAN-2005-0469 to these issues.

Additionally, the following bugs have been fixed in these erratum packages
for Red Hat Enterprise Linux 2.1 and Red Hat Enterprise Linux 3:

- telnetd could loop on an error in the child side process

- There was a race condition in telnetd on a wtmp lock on some occasions

- The command line in the process table was sometimes too long and caused
bad output from the ps command

- The 8-bit binary option was not working

Users of telnet should upgrade to this updated package, which contains
backported patches to correct these issues.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/126858" id="126858">Too long /proc/X/cmdline: bad ps output when piped to less/more</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145004" id="145004">telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145636" id="145636">[PATCH] telnetd loops on child IO error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147003" id="147003">[RHEL3] telnetd cleanup() race condition with syslog in signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151297" id="151297">CAN-2005-0469 slc_add_reply() Buffer Overflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151301" id="151301">CAN-2005-0468 env_opt_add() Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327002" comment="telnet is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327004" comment="telnet-server is earlier than 1:0.17-26.EL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327007" comment="telnet is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050327008" comment="telnet-server is earlier than 1:0.17-31.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050330" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:330: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:330-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-330.html" />
          <reference source="CVE" ref_id="CVE-2005-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0468.html" />
          <reference source="CVE" ref_id="CVE-2005-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0469.html" />
    
    <description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

The krb5-workstation package includes a Kerberos-aware telnet client. 
Two buffer overflow flaws were discovered in the way the telnet client
handles messages from a server.  An attacker may be able to execute
arbitrary code on a victim's machine if the victim can be tricked into
connecting to a malicious telnet server. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-0468 and
CAN-2005-0469 to these issues.

Users of krb5 should update to these erratum packages which contain a
backported patch to correct this issue.

Red Hat would like to thank iDEFENSE for their responsible disclosure of
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0468.html">CVE-2005-0468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0469.html">CVE-2005-0469</cve>
                <bugzilla href="http://bugzilla.redhat.com/151267" id="151267">CAN-2005-0469  Multiple Telnet Client issues (CAN-2005-0468)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330006" comment="krb5-libs is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330004" comment="krb5-devel is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330008" comment="krb5-server is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330002" comment="krb5 is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330010" comment="krb5-workstation is earlier than 0:1.2.7-42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330015" comment="krb5-libs is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330014" comment="krb5-devel is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330016" comment="krb5-server is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330013" comment="krb5 is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050330017" comment="krb5-workstation is earlier than 0:1.3.4-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050331" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:331: XFree86 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:331-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-331.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>XFree86 is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

An integer overflow flaw was found in libXpm, which is used by some
applications for loading of XPM images. An attacker could create a
malicious XPM file that would execute arbitrary code if opened by a victim
using an application linked to the vulnerable library. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0605 to this issue.

The updated XFree86 packages also address the following minor issues:

- Updated XFree86-4.3.0-keyboard-disable-ioport-access-v3.patch to make
  warning messages less alarmist.

- Backported XFree86-4.3.0-libX11-stack-overflow.patch from xorg-x11-6.8.1
  packaging to fix stack overflow in libX11, which was discovered by new
  security features of gcc4.

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-30" />
        <updated date="2005-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/132885" id="132885">libX11 overflows it's own stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150038" id="150038">CAN-2005-0605 XPM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331043" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331012" comment="XFree86-xdm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331013" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331016" comment="XFree86-libs-data is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331017" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331046" comment="XFree86-doc is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331047" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331045" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331031" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331002" comment="XFree86 is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331057" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331021" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331014" comment="XFree86-libs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331015" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331060" comment="XFree86-sdk is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331025" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331008" comment="XFree86-xfs is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331009" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331048" comment="XFree86-Xnest is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331049" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331037" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331023" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331041" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331035" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331058" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331059" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331027" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331039" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331018" comment="XFree86-base-fonts is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331019" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331006" comment="XFree86-font-utils is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331007" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331052" comment="XFree86-tools is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331053" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331050" comment="XFree86-Xvfb is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331051" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331010" comment="XFree86-twm is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331011" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331054" comment="XFree86-xauth is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331055" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050331004" comment="XFree86-devel is earlier than 0:4.3.0-81.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331005" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050332" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:332: xloadimage security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-332.html" />
          <reference source="CVE" ref_id="CVE-2005-0638" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0638.html" />
    
    <description>The xloadimage utility displays images in an X Window System window,
loads images into the root window, or writes images into a file.
Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM,
and XBM).

A flaw was discovered in xloadimage where filenames were not properly
quoted when calling the gunzip command.  An attacker could create a file
with a carefully crafted filename so that it would execute arbitrary
commands if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0638 to
this issue.

Another bug in xloadimage would cause it to crash if called with certain
invalid TIFF, PNM, PBM, or PPM file names.

All users of xloadimage should upgrade to this erratum package which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-04-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0638.html">CVE-2005-0638</cve>
                <bugzilla href="http://bugzilla.redhat.com/70867" id="70867">xloadimage crashes with some TIFF images</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/78481" id="78481">bad source code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150700" id="150700">CAN-2005-0638 xloadimage multiple issues.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332002" comment="xloadimage is earlier than 0:4.1-34.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332005" comment="xloadimage is earlier than 0:4.1-34.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050334" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:334: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:334-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-334.html" />
          <reference source="CVE" ref_id="CVE-2005-0709" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0709.html" />
          <reference source="CVE" ref_id="CVE-2005-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0710.html" />
          <reference source="CVE" ref_id="CVE-2005-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0711.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server.

This update fixes several security risks in the MySQL server.

Stefano Di Paola discovered two bugs in the way MySQL handles user-defined
functions. A user with the ability to create and execute a user defined
function could potentially execute arbitrary code on the MySQL server. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2005-0709 and CAN-2005-0710 to these issues.

Stefano Di Paola also discovered a bug in the way MySQL creates temporary
tables. A local user could create a specially crafted symlink which could
result in the MySQL server overwriting a file which it has write access to.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-0711 to this issue.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-28" />
        <updated date="2005-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0709.html">CVE-2005-0709</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0710.html">CVE-2005-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0711.html">CVE-2005-0711</cve>
                <bugzilla href="http://bugzilla.redhat.com/150868" id="150868">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150871" id="150871">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151051" id="151051">CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152344" id="152344">CAN-2005-0711 Insecure temporary file creation with CREATE TEMPORARY TABLE</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334002" comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334004" comment="mysql-server is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334008" comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334006" comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334011" comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334012" comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334014" comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050334013" comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050335" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:335: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:335-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-335.html" />
          <reference source="CVE" ref_id="CVE-2004-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1380.html" />
          <reference source="CVE" ref_id="CVE-2005-0141" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0141.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0144.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0149" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0149.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A buffer overflow bug was found in the way Mozilla processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Mozilla responds to proxy auth requests. It is
possible for a malicious webserver to steal credentials from a victims
browser by issuing a 407 proxy authentication request. (CAN-2005-0147)

A bug was found in the way Mozilla displays dialog windows. It is possible
that a malicious web page which is being displayed in a background tab
could present the user with a dialog window appearing to come from the
active page. (CAN-2004-1380)

A bug was found in the way Mozilla Mail handles cookies when loading
content over HTTP regardless of the user's preference. It is possible that
a particular user could be tracked through the use of malicious mail
messages which load content over HTTP. (CAN-2005-0149)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A bug was found in the way Mozilla saves temporary files. Temporary files
are saved with world readable permissions, which could allow a local
malicious user to view potentially sensitive data. (CAN-2005-0142)

A bug was found in the way Mozilla handles synthetic middle click events. 
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

A bug was found in the way Mozilla processes XUL content.  If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla loads links in a new tab which are
middle clicked. A malicious web page could read local files or modify
privileged chrom settings. (CAN-2005-0141)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can use a view-source URL targetted at a secure page,
while loading an insecure page, yet the secure site icon shows the previous
secure state. (CAN-2005-0144)

A bug was found in the way Mozilla displays the secure site icon. A
malicious web page can display the secure site icon by loading a binary
file from a secured site. (CAN-2005-0143)

A bug was found in the way Mozilla displays the download dialog window. A
malicious site can obfuscate the content displayed in the source field,
tricking a user into thinking they are downloading content from a trusted
source. (CAN-2005-0585)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.6 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1380.html">CVE-2004-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0141.html">CVE-2005-0141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0144.html">CVE-2005-0144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0149.html">CVE-2005-0149</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
                <bugzilla href="http://bugzilla.redhat.com/142508" id="142508">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144228" id="144228">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146188" id="146188">CAN-2005-0141 multiple mozilla issues CAN-2004-1316 CAN-2005-0142 CAN-2005-0143 CAN-2005-0144 CAN-2004-1380 CAN-2004-1381 CAN-2005-0146 CAN-2005-0147 CAN-2005-0149</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150866" id="150866">CAN-2005-0399 mozilla GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151730" id="151730">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335018" comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335014" comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335016" comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335010" comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335002" comment="mozilla is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335020" comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335006" comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335004" comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335012" comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335008" comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335022" comment="devhelp is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335026" comment="evolution is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050335028" comment="evolution-devel is earlier than 0:2.0.2-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050336" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:336: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-336.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0402.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A buffer overflow bug was found in the way Firefox processes GIF images. It
is possible for an attacker to create a specially crafted GIF image, which
when viewed by a victim will execute arbitrary code as the victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0399 to this issue.

A bug was found in the way Firefox processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0401 to this issue.

A bug was found in the way Firefox bookmarks content to the sidebar. If a
user can be tricked into bookmarking a malicious web page into the sidebar
panel, that page could execute arbitrary programs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0402 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0402.html">CVE-2005-0402</cve>
                <bugzilla href="http://bugzilla.redhat.com/150877" id="150877">CAN-2005-0399 firefox GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151153" id="151153">CAN-2005-0402 arbitrary code execution via sidebar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151714" id="151714">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050336002" comment="firefox is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050337" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:337: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-337.html" />
          <reference source="CVE" ref_id="CVE-2005-0399" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0399.html" />
          <reference source="CVE" ref_id="CVE-2005-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0255.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A buffer overflow bug was found in the way Thunderbird processes GIF
images. It is possible for an attacker to create a specially crafted GIF
image, which when viewed by a victim will execute arbitrary code as the
victim. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0399 to this issue.

A bug was found in the Thunderbird string handling functions. If a
malicious website is able to exhaust a system's memory, it becomes possible
to execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0255 to this issue.

Users of Thunderbird are advised to upgrade to this updated package which
contains Thunderbird version 1.0.2 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0399.html">CVE-2005-0399</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0255.html">CVE-2005-0255</cve>
                <bugzilla href="http://bugzilla.redhat.com/149883" id="149883">CAN-2005-0255 Memory overwrite in string library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150874" id="150874">CAN-2005-0399 thunderbird GIF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050337002" comment="thunderbird is earlier than 0:1.0.2-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050340" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:340: curl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:340-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-340.html" />
          <reference source="CVE" ref_id="CVE-2005-0490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0490.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and
Dict servers, using any of the supported protocols. cURL is designed
to work without user interaction or any kind of interactivity. 

Multiple buffer overflow bugs were found in the way curl processes base64
encoded replies. If a victim can be tricked into visiting a URL with curl,
a malicious web server could execute arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0490 to this issue.

All users of curl are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0490.html">CVE-2005-0490</cve>
                <bugzilla href="http://bugzilla.redhat.com/149322" id="149322">CAN-2005-0490 Multiple stack based buffer overflows in curl</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340002" comment="curl is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340004" comment="curl-devel is earlier than 0:7.10.6-6.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340007" comment="curl is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050340008" comment="curl-devel is earlier than 0:7.12.1-5.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050343" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:343: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:343-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-343.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gdk-pixbuf. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gdk-pixbuf are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-05" />
        <updated date="2005-04-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152315" id="152315">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343002" comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050343009" comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050344" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:344: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-344.html" />
          <reference source="CVE" ref_id="CVE-2005-0891" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0891.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System. 

A bug was found in the way gtk2 processes BMP images. It is possible
that a specially crafted BMP image could cause a denial of service attack
on applications linked against gtk2. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0891 to
this issue.

Users of gtk2 are advised to upgrade to these packages, which contain
a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0891.html">CVE-2005-0891</cve>
                <bugzilla href="http://bugzilla.redhat.com/152317" id="152317">CAN-2005-0891 gdk-pixbuf BMP double free DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344002" comment="gtk2 is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344004" comment="gtk2-devel is earlier than 0:2.2.4-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344007" comment="gtk2 is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050344008" comment="gtk2-devel is earlier than 0:2.4.13-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050345" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:345: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:345-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-345.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- Files with a size of 2 GB and larger were not entered into the slocate
  database.

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems).

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/132571" id="132571">Files > 2 GB are not entered into slocate data base</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169453" id="169453">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050345002" comment="slocate is earlier than 0:2.7-3.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050345003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050346" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:346: slocate security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-346.html" />
          <reference source="CVE" ref_id="CVE-2005-2499" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2499.html" />
    
    <description>Slocate is a security-enhanced version of locate. Like locate, slocate
searches through a central database (updated nightly) for files that match
a given pattern. Slocate allows you to quickly find files anywhere on your
system.

A bug was found in the way slocate scans the local filesystem. A carefully
prepared directory structure could cause updatedb's file system scan to
fail silently, resulting in an incomplete slocate database. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2499
to this issue.

Additionally this update addresses the following issues:

- File system type exclusions were processed only when starting updatedb 
  and did not reflect file systems mounted while updatedb was running 
  (for example, automounted file systems.)

- File system type exclusions were ignored for file systems that were
  mounted to a path containing a symbolic link.

- Databases created by slocate were owned by the slocate group even if they
  were created by regular users.

- The default configuration excluded /mnt/floppy, but not /media.

- The default configuration did not exclude nfs4 file systems.

Users of slocate are advised to upgrade to this updated package, which
contains backported patches and is not affected by these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2499.html">CVE-2005-2499</cve>
                <bugzilla href="http://bugzilla.redhat.com/139950" id="139950">slocate collects .automount files over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152253" id="152253">Incorrect path in /etc/updatedb.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156091" id="156091">updatedb indexes nfs4 filesystems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165430" id="165430">CAN-2005-2499 slocate DOS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050346002" comment="slocate is earlier than 0:2.7-13.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050345003" comment="slocate is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050354" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:354: tetex security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-354.html" />
          <reference source="CVE" ref_id="CVE-2004-0803" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0803.html" />
          <reference source="CVE" ref_id="CVE-2004-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0804.html" />
          <reference source="CVE" ref_id="CVE-2004-0886" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0886.html" />
          <reference source="CVE" ref_id="CVE-2004-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0888.html" />
          <reference source="CVE" ref_id="CVE-2004-1125" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1125.html" />
    
    <description>TeTeX is an implementation of TeX for Linux or UNIX systems. TeX takes
a text file and a set of formatting commands as input and creates a
typesetter-independent .dvi (DeVice Independent) file as output.

A number of security flaws have been found affecting libraries used
internally within teTeX.  An attacker who has the ability to trick a user
into processing a malicious file with teTeX could cause teTeX to crash or
possibly execute arbitrary code. 

A number of integer overflow bugs that affect Xpdf were discovered. The
teTeX package contains a copy of the Xpdf code used for parsing PDF files
and is therefore affected by these bugs. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2004-0888 and
CAN-2004-1125 to these issues.

A number of integer overflow bugs that affect libtiff were discovered.  The
teTeX package contains an internal copy of libtiff used for parsing TIFF
image files and is therefore affected by these bugs.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0803, CAN-2004-0804 and CAN-2004-0886 to these issues.

Also latex2html is added to package tetex-latex for 64bit platforms.

Users of teTeX should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-01" />
        <updated date="2005-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0803.html">CVE-2004-0803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0804.html">CVE-2004-0804</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0886.html">CVE-2004-0886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0888.html">CVE-2004-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1125.html">CVE-2004-1125</cve>
                <bugzilla href="http://bugzilla.redhat.com/137475" id="137475">CAN-2004-0888 xpdf integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137607" id="137607">CAN-2004-0803 multiple issues in libtiff (CAN-2004-0804 CAN-2004-0886)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137973" id="137973">tetex-latex package missing latex2html</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145129" id="145129">CAN-2004-1125 xpdf buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354006" comment="tetex-xdvi is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354002" comment="tetex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354012" comment="tetex-fonts is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354014" comment="tetex-doc is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354004" comment="tetex-latex is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354008" comment="tetex-dvips is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050354010" comment="tetex-afm is earlier than 0:1.0.7-67.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050357" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:357: gzip security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-357.html" />
          <reference source="CVE" ref_id="CVE-2005-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0758.html" />
          <reference source="CVE" ref_id="CVE-2005-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0988.html" />
          <reference source="CVE" ref_id="CVE-2005-1228" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1228.html" />
    
    <description>The gzip package contains the GNU gzip data compression program.

A bug was found in the way zgrep processes file names. If a user can be
tricked into running zgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running zgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0758 to this issue.

A bug was found in the way gunzip modifies permissions of files being
decompressed. A local attacker with write permissions in the directory in
which a victim is decompressing a file could remove the file being written
and replace it with a hard link to a different file owned by the victim. 
gunzip then gives the linked file the permissions of the uncompressed file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0988 to this issue.

A directory traversal bug was found in the way gunzip processes the -N
flag. If a victim decompresses a file with the -N flag, gunzip fails to
sanitize the path which could result in a file owned by the victim being
overwritten. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1228 to this issue.

Users of gzip should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0758.html">CVE-2005-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0988.html">CVE-2005-0988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1228.html">CVE-2005-1228</cve>
                <bugzilla href="http://bugzilla.redhat.com/121514" id="121514">CAN-2005-0758 zgrep has security issue in sed usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155745" id="155745">CAN-2005-0988 Race condition in gzip</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156266" id="156266">CAN-2005-1228 directory traversal bug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357002" comment="gzip is earlier than 0:1.3.3-12.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357005" comment="gzip is earlier than 0:1.3.3-15.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050357003" comment="gzip is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050358" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:358: exim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:358-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-358.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet.

An integer overflow flaw was found in PCRE, a Perl-compatible regular
expression library included within Exim.  A local user could create a
maliciously crafted regular expression in such as way that they could gain
the privileges of the 'exim' user.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2491 to this issue.  These
erratum packages change Exim to use the system PCRE library instead of the
internal one.  

These packages also fix a minor flaw where the Exim Monitor was incorrectly
computing free space on very large file systems.

Users should upgrade to these erratum packages and also ensure they have
updated the system PCRE library, for which erratum packages are available
seperately in RHSA-2005:761</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166332" id="166332">CAN-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358004" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-mon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358006" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358002" comment="exim is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050358008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050361" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:361: vixie-cron security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-361.html" />
          <reference source="CVE" ref_id="CVE-2005-1038" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1038.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

A bug was found in the way vixie-cron installs new crontab files. It is
possible for a local attacker to execute the crontab command in such a way
that they can view the contents of another user's crontab file. The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1038 to
this issue. 

Additionally, this update addresses the following issues:

o Fixed improper limits on filename and command line lengths 
o Improved PAM access control conforming to EAL certification requirements
o Improved reliability when running in a chroot environment
o Mail recipient name checking disabled by default, can be re-enabled 
o Added '-p' "permit all crontabs" option to disable crontab mode checking

All users of vixie-cron should upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1038.html">CVE-2005-1038</cve>
                <bugzilla href="http://bugzilla.redhat.com/147636" id="147636">cron fails to run user jobs and gives vague error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154920" id="154920">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159216" id="159216">vixie-cron updates for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163881" id="163881">Cron no longer allows read-only crontabs, enforces write access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163882" id="163882">cron fails with pam_access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163885" id="163885">crontab truncates file names greater than 100 characters.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163888" id="163888">CAN-2005-1038 vixie-cron information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163889" id="163889">[PATCH] List corruption when items are removed from /etc/cron.d</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361002" comment="vixie-cron is earlier than 4:4.1-36.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050361003" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050365" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:365: gaim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:365-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-365.html" />
          <reference source="CVE" ref_id="CVE-2005-0965" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0965.html" />
          <reference source="CVE" ref_id="CVE-2005-0966" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0966.html" />
          <reference source="CVE" ref_id="CVE-2005-0967" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0967.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

A buffer overflow bug was found in the way gaim escapes HTML. It is
possible that a remote attacker could send a specially crafted message to a
Gaim client, causing it to crash. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0965 to this issue.

A bug was found in several of gaim's IRC processing functions. These
functions fail to properly remove various markup tags within an IRC
message. It is possible that a remote attacker could send a specially
crafted message to a Gaim client connected to an IRC server, causing it to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0966 to this issue.

A bug was found in gaim's Jabber message parser. It is possible for a
remote Jabber user to send a specially crafted message to a Gaim client,
causing it to crash. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0967 to this issue.

In addition to these denial of service issues, multiple minor upstream
bugfixes are included in this update.

Users of Gaim are advised to upgrade to this updated package which contains
Gaim version 1.2.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-12" />
        <updated date="2005-04-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0965.html">CVE-2005-0965</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0966.html">CVE-2005-0966</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0967.html">CVE-2005-0967</cve>
                <bugzilla href="http://bugzilla.redhat.com/153311" id="153311">CAN-2005-0965 Gaim remote DoS issues (CAN-2005-0966)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153761" id="153761">CAN-2005-0967 jabber DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365002" comment="gaim is earlier than 1:1.2.1-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050365005" comment="gaim is earlier than 1:1.2.1-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050366" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:366: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:366-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-366.html" />
          <reference source="CVE" ref_id="CVE-2005-0135" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0135.html" />
          <reference source="CVE" ref_id="CVE-2005-0207" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0207.html" />
          <reference source="CVE" ref_id="CVE-2005-0210" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0210.html" />
          <reference source="CVE" ref_id="CVE-2005-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0384.html" />
          <reference source="CVE" ref_id="CVE-2005-0400" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0400.html" />
          <reference source="CVE" ref_id="CVE-2005-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0449.html" />
          <reference source="CVE" ref_id="CVE-2005-0529" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0529.html" />
          <reference source="CVE" ref_id="CVE-2005-0530" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0530.html" />
          <reference source="CVE" ref_id="CVE-2005-0531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0531.html" />
          <reference source="CVE" ref_id="CVE-2005-0736" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0736.html" />
          <reference source="CVE" ref_id="CVE-2005-0749" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0749.html" />
          <reference source="CVE" ref_id="CVE-2005-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0750.html" />
          <reference source="CVE" ref_id="CVE-2005-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0767.html" />
          <reference source="CVE" ref_id="CVE-2005-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0815.html" />
          <reference source="CVE" ref_id="CVE-2005-0839" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0839.html" />
          <reference source="CVE" ref_id="CVE-2005-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0867.html" />
          <reference source="CVE" ref_id="CVE-2005-0977" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0977.html" />
          <reference source="CVE" ref_id="CVE-2005-1041" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1041.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw in the fib_seq_start function was discovered. A local user could use
this flaw to cause a denial of service (system crash) via /proc/net/route.
(CAN-2005-1041)

A flaw in the tmpfs file system was discovered. A local user could use this
flaw to cause a denial of service (system crash). (CAN-2005-0977)

An integer overflow flaw was found when writing to a sysfs file. A local
user could use this flaw to overwrite kernel memory, causing a denial of
service (system crash) or arbitrary code execution. (CAN-2005-0867)

Keith Owens reported a flaw in the Itanium unw_unwind_to_user function. A
local user could use this flaw to cause a denial of service (system crash)
on Itanium architectures. (CAN-2005-0135)

A flaw in the NFS client O_DIRECT error case handling was discovered. A
local user could use this flaw to cause a denial of service (system crash).
(CAN-2005-0207)

A small memory leak when defragmenting local packets was discovered that
affected the Linux 2.6 kernel netfilter subsystem.  A local user could send
a large number of carefully crafted fragments leading to memory exhaustion
(CAN-2005-0210)

A flaw was discovered in the Linux PPP driver. On systems allowing remote
users to connect to a server using ppp, a remote client could cause a
denial of service (system crash). (CAN-2005-0384)

A flaw was discovered in the ext2 file system code. When a new directory is
created, the ext2 block written to disk is not initialized, which could
lead to an information leak if a disk image is made available to
unprivileged users. (CAN-2005-0400)

A flaw in fragment queuing was discovered that affected the Linux kernel
netfilter subsystem. On systems configured to filter or process network
packets (e.g. firewalling), a remote attacker could send a carefully
crafted set of fragmented packets to a machine and cause a denial of
service (system crash). In order to sucessfully exploit this flaw, the
attacker would need to know or guess some aspects of the firewall ruleset
on the target system. (CAN-2005-0449)

A number of flaws were found in the Linux 2.6 kernel. A local user could
use these flaws to read kernel memory or cause a denial of service (crash).
(CAN-2005-0529, CAN-2005-0530, CAN-2005-0531)

An integer overflow in sys_epoll_wait in eventpoll.c was discovered. A
local user could use this flaw to overwrite low kernel memory. This memory
is usually unused, not usually resulting in a security consequence.
(CAN-2005-0736)

A flaw when freeing a pointer in load_elf_library was discovered. A local
user could potentially use this flaw to cause a denial of service (crash).
(CAN-2005-0749)

A flaw was discovered in the bluetooth driver system. On systems where the
bluetooth modules are loaded, a local user could use this flaw to gain
elevated (root) privileges. (CAN-2005-0750)

A race condition was discovered that affected the Radeon DRI driver. A
local user who has DRI privileges on a Radeon graphics card may be able to
use this flaw to gain root privileges. (CAN-2005-0767)

Multiple range checking flaws were discovered in the iso9660 file system
handler. An attacker could create a malicious file system image which would
cause a denial or service or potentially execute arbitrary code if mounted.
(CAN-2005-0815)

A flaw was discovered when setting line discipline on a serial tty. A local
user may be able to use this flaw to inject mouse movements or keystrokes
when another user is logged in. (CAN-2005-0839)

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.

Please note that</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-19" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0135.html">CVE-2005-0135</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0207.html">CVE-2005-0207</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0210.html">CVE-2005-0210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0384.html">CVE-2005-0384</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0400.html">CVE-2005-0400</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0449.html">CVE-2005-0449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0529.html">CVE-2005-0529</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0530.html">CVE-2005-0530</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0531.html">CVE-2005-0531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0736.html">CVE-2005-0736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0749.html">CVE-2005-0749</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0750.html">CVE-2005-0750</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0767.html">CVE-2005-0767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0815.html">CVE-2005-0815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0839.html">CVE-2005-0839</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0867.html">CVE-2005-0867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0977.html">CVE-2005-0977</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1041.html">CVE-2005-1041</cve>
                <bugzilla href="http://bugzilla.redhat.com/147468" id="147468">CAN-2005-0449 Possible remote Oops/firewall bypass - kABI breaker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148868" id="148868">CAN-2005-0135 ia64 local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148878" id="148878">CAN-2005-0207 nfs client O_DIRECT oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149466" id="149466">CAN-2005-0529 Sign handling issues on v2.6 (CAN-2005-0530 CAN-2005-0531)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149589" id="149589">CAN-2005-0209 netfilter SKB problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151240" id="151240">CAN-2005-0384 pppd remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151249" id="151249">CAN-2005-0736 epoll overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151902" id="151902">CAN-2005-0767 drm race in radeon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152177" id="152177">CAN-2005-0750 bluetooth security flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152399" id="152399">CAN-2005-0400 ext2 mkdir() directory entry random kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152405" id="152405">CAN-2005-0815 isofs range checking flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152410" id="152410">CAN-2005-0749 load_elf_library possible DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152417" id="152417">CAN-2005-0839 N_MOUSE line discipline flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152561" id="152561">CAN-2005-0977 tmpfs truncate bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154219" id="154219">CAN-2005-0867 sysfs signedness problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154551" id="154551">CAN-2005-1041 crash while reading /proc/net/route</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366002" comment="kernel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366006" comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366004" comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366010" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366012" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050366008" comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050373" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:373: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-373.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management.

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet which will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc which can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally the following bugs have been fixed:
 - snmpwalk no longer hangs when a non-existant pid is listed. 
 - snmpd no longer segfaults due to incorrect handling of lmSensors. 
 - an incorrect assignment leading to invalid values in ASN mibs has been
   fixed.
 - on systems running a 64-bit kernel, the values in /proc/net/dev no 
   longer become too large to fit in a 32-bit object. 
 - the net-snmp-devel packages correctly depend on elfutils-libelf-devel.
 - large file systems are correctly handled
 - snmp daemon now reports gigabit Ethernet speeds correctly
 - fixed consistency between IP adresses and hostnames in configuration file

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/130252" id="130252">net-snmp-devel should depend on elfutils-libelf-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152448" id="152448">snmpd.conf hostname vs. IP inconsistancy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162907" id="162907">CAN-2005-2177 net-snmp denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164639" id="164639">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373004" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373005" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373010" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373008" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373009" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373006" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373007" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050373002" comment="net-snmp is earlier than 0:5.0.9-2.30E.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050375" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:375: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:375-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-375.html" />
          <reference source="CVE" ref_id="CVE-2005-0941" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0941.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap based buffer overflow bug was found in the OpenOffice.org DOC file
processor. An attacker could create a carefully crafted DOC file in such a
way that it could cause OpenOffice.org to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0941 to this issue.

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0941.html">CVE-2005-0941</cve>
                <bugzilla href="http://bugzilla.redhat.com/154540" id="154540">CAN-2005-0941 openoffice.org heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375006" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375002" comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375004" comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375011" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375009" comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375012" comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050375010" comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050375005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050377" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:377: sharutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-377.html" />
          <reference source="CVE" ref_id="CVE-2004-1772" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1772.html" />
          <reference source="CVE" ref_id="CVE-2004-1773" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1773.html" />
          <reference source="CVE" ref_id="CVE-2005-0990" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0990.html" />
    
    <description>The sharutils package contains a set of tools for encoding and decoding
packages of files in binary or text format.

A stack based overflow bug was found in the way shar handles the -o option.
If a user can be tricked into running a specially crafted command, it could
lead to arbitrary code execution.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-1772 to this issue.
Please note that this issue does not affect Red Hat Enterprise Linux 4.

Two buffer overflow bugs were found in sharutils. If an attacker can place
a malicious 'wc' command on a victim's machine, or trick a victim into
running a specially crafted command, it could lead to arbitrary code
execution.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1773 to this issue.

A bug was found in the way unshar creates temporary files. A local user
could use symlinks to overwrite arbitrary files the victim running unshar
has write access to. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0990 to this issue.

All users of sharutils should upgrade to this updated package, which
includes backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1772.html">CVE-2004-1772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1773.html">CVE-2004-1773</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0990.html">CVE-2005-0990</cve>
                <bugzilla href="http://bugzilla.redhat.com/152571" id="152571">CAN-2004-1772 buffer overflow with -o option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152573" id="152573">CAN-2004-1773 Buffer overflows in unshar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154049" id="154049">CAN-2005-0990 insecure temp file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377002" comment="sharutils is earlier than 0:4.2.1-16.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377005" comment="sharutils is earlier than 0:4.2.1-22.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050377003" comment="sharutils is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050378" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:378: cpio security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:378-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-378.html" />
          <reference source="CVE" ref_id="CVE-2005-1111" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1111.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive. 

A race condition bug was found in cpio. It is possible for a local
malicious user to modify the permissions of a local file if they have write
access to a directory in which a cpio archive is being extracted. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1111 to this issue.

Additionally, this update adds cpio support for archives larger than 2GB.
However, the size of individual files within an archive is limited to 4GB.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1111.html">CVE-2005-1111</cve>
                <bugzilla href="http://bugzilla.redhat.com/105617" id="105617">cpio does not support large files > 2GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144688" id="144688">cpio fails to unpack initrd on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154507" id="154507">511278 - needs fix for RHEL 4 on cpio bugzilla 105617</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155749" id="155749">CVE-2005-1111 Race condition in cpio</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378002" comment="cpio is earlier than 0:2.5-4.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050378005" comment="cpio is earlier than 0:2.5-8.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050073003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050381" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:381: nasm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:381-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-381.html" />
          <reference source="CVE" ref_id="CVE-2004-1287" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1287.html" />
          <reference source="CVE" ref_id="CVE-2005-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1194.html" />
    
    <description>NASM is an 80x86 assembler.

Two stack based buffer overflow bugs have been found in nasm. An attacker
could create an ASM file in such a way that when compiled by a victim,
could execute arbitrary code on their machine. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1287
and CAN-2005-1194 to these issues.

All users of nasm are advised to upgrade to this updated package, which
contains backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1287.html">CVE-2004-1287</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1194.html">CVE-2005-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/143081" id="143081">CAN-2004-1287 Bernstein class reports buffer overflow in nasm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152962" id="152962">CAN-2005-1194 Buffer overflow in the ieee_putascii() function</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381004" comment="nasm-doc is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381002" comment="nasm is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381006" comment="nasm-rdoff is earlier than 0:0.98.35-3.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381010" comment="nasm-doc is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381005" comment="nasm-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381009" comment="nasm is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381003" comment="nasm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050381011" comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050381007" comment="nasm-rdoff is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050383" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:383: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:383-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-383.html" />
          <reference source="CVE" ref_id="CVE-2005-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0752.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1158" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1158.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Vladimir V. Perepelitsa discovered a bug in the way Firefox handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Omar Khan discovered a bug in the way Firefox processes the PLUGINSPAGE
tag. It is possible for a malicious web page to trick a user into pressing
the "manual install" button for an unknown plugin leading to arbitrary
javascript code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0752 to this issue.

Doron Rosenberg discovered a bug in the way Firefox displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1153 to this issue.

A bug was found in the way Firefox handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1154 to
this issue.

Michael Krax discovered a bug in the way Firefox handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1155 to this issue.

Michael Krax discovered a bug in the way Firefox installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and steal sensitive information.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2005-1156 and CAN-2005-1157 to these issues. 

Kohei Yoshino discovered a bug in the way Firefox opens links in its
sidebar. A malicious web page could construct a link in such a way that,
when clicked on, could execute arbitrary javascript with elevated
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1158 to this issue.

A bug was found in the way Firefox validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1159 to this issue.

A bug was found in the way the Firefox privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1160 to this issue.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.3 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-21" />
        <updated date="2005-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0752.html">CVE-2005-0752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1158.html">CVE-2005-1158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155114" id="155114">CAN-2005-0752 Multiple firefox issues. (CAN-2005-0989)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050383002" comment="firefox is earlier than 0:1.0.3-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050384" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:384: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-384.html" />
          <reference source="CVE" ref_id="CVE-2004-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0142.html" />
          <reference source="CVE" ref_id="CVE-2005-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0143.html" />
          <reference source="CVE" ref_id="CVE-2005-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0146.html" />
          <reference source="CVE" ref_id="CVE-2005-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0231.html" />
          <reference source="CVE" ref_id="CVE-2005-0232" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0232.html" />
          <reference source="CVE" ref_id="CVE-2005-0233" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0233.html" />
          <reference source="CVE" ref_id="CVE-2005-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0401.html" />
          <reference source="CVE" ref_id="CVE-2005-0527" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0527.html" />
          <reference source="CVE" ref_id="CVE-2005-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0578.html" />
          <reference source="CVE" ref_id="CVE-2005-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0584.html" />
          <reference source="CVE" ref_id="CVE-2005-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0585.html" />
          <reference source="CVE" ref_id="CVE-2005-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0586.html" />
          <reference source="CVE" ref_id="CVE-2005-0588" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0588.html" />
          <reference source="CVE" ref_id="CVE-2005-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0590.html" />
          <reference source="CVE" ref_id="CVE-2005-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0591.html" />
          <reference source="CVE" ref_id="CVE-2005-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0593.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found with the way Mozilla displays the secure site icon.
It is possible that a malicious website could display the secure site icon
along with incorrect certificate information. (CAN-2005-0143 CAN-2005-0593)

A bug was found in the way Mozilla handles synthetic middle click events.
It is possible for a malicious web page to steal the contents of a victims
clipboard. (CAN-2005-0146)

Several bugs were found with the way Mozilla handles temporary files. A
local user could view sensitive temporary information or delete arbitrary
files. (CAN-2005-0142 CAN-2005-0578)

A bug was found in the way Mozilla handles pop-up windows. It is possible
for a malicious website to control the content in an unrelated site's
pop-up window. (CAN-2004-1156)

A flaw was found in the way Mozilla displays international domain names. It
is possible for an attacker to display a valid URL, tricking the user into
thinking they are viewing a legitimate webpage when they are not.
(CAN-2005-0233)

A bug was found in the way Mozilla processes XUL content. If a malicious
web page can trick a user into dragging an object, it is possible to load
malicious XUL content. (CAN-2005-0401)

A bug was found in the way Mozilla handles xsl:include and xsl:import
directives. It is possible for a malicious website to import XSLT
stylesheets from a domain behind a firewall, leaking information to an
attacker. (CAN-2005-0588)

Several bugs were found in the way Mozilla displays alert dialogs. It is
possible for a malicious webserver or website to trick a user into thinking
the dialog window is being generated from a trusted site. (CAN-2005-0586
CAN-2005-0591 CAN-2005-0585 CAN-2005-0590 CAN-2005-0584)

A bug was found in the Mozilla javascript security manager. If a user drags
a malicious link to a tab, the javascript security manager is bypassed,
which could result in remote code execution or information disclosure.
(CAN-2005-0231)

A bug was found in the way Mozilla allows plug-ins to load privileged
content into a frame. It is possible that a malicious webpage could trick a
user into clicking in certain places to modify configuration settings or
execute arbitrary code. (CAN-2005-0232 and CAN-2005-0527)

A bug was found in the way Mozilla handles anonymous functions during
regular expression string replacement. It is possible for a malicious web
page to capture a random block of browser memory. (CAN-2005-0989)

A bug was found in the way Mozilla displays pop-up windows. If a user
choses to open a pop-up window whose URL is malicious javascript, the
script will be executed with elevated privileges. (CAN-2005-1153)

A bug was found in the way Mozilla installed search plugins. If a user
chooses to install a search plugin from a malicious site, the new plugin
could silently overwrite an existing plugin. This could allow the malicious
plugin to execute arbitrary code and stealm sensitive information.
(CAN-2005-1156 CAN-2005-1157)

Several bugs were found in the Mozilla javascript engine. A malicious web
page could leverage these issues to execute javascript with elevated
privileges or steal sensitive information. (CAN-2005-1154 CAN-2005-1155
CAN-2005-1159 CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1156.html">CVE-2004-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0142.html">CVE-2005-0142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0143.html">CVE-2005-0143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0146.html">CVE-2005-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0231.html">CVE-2005-0231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0232.html">CVE-2005-0232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0233.html">CVE-2005-0233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0401.html">CVE-2005-0401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0527.html">CVE-2005-0527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0578.html">CVE-2005-0578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0584.html">CVE-2005-0584</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0585.html">CVE-2005-0585</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0586.html">CVE-2005-0586</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0588.html">CVE-2005-0588</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0590.html">CVE-2005-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0591.html">CVE-2005-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0593.html">CVE-2005-0593</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/142390" id="142390">CAN-2004-1156 Frame injection vulnerability.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144080" id="144080">CAN-2005-0585 download dialog URL spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145606" id="145606">CAN-2005-0142 Opened attachments are temporarily saved world-readable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145607" id="145607">CAN-2005-0143 Secure site lock can be spoofed with a binary download</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145613" id="145613">CAN-2005-0146 Synthetic middle-click event can steal clipboard contents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147397" id="147397">CAN-2005-0233 homograph spoofing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151722" id="151722">CAN-2005-0401 Drag and drop loading of privileged XUL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152580" id="152580">CAN-2005-0578 Mozilla issues (CAN-2005-0232 CAN-2005-0527 CAN-2005-0231 CAN-2005-0584 CAN-2005-0585 CAN-2005-0586 CAN-2005-0588 CAN-2005-0590 CAN-2005-0591 CAN-2005-0593)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155117" id="155117">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384014" comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384016" comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384002" comment="mozilla is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384004" comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384012" comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050384008" comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050386" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:386: Mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:386-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-386.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1153" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1153.html" />
          <reference source="CVE" ref_id="CVE-2005-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1154.html" />
          <reference source="CVE" ref_id="CVE-2005-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1155.html" />
          <reference source="CVE" ref_id="CVE-2005-1156" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1156.html" />
          <reference source="CVE" ref_id="CVE-2005-1157" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1157.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Vladimir V. Perepelitsa discovered a bug in the way Mozilla handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-0989 to this issue.

Doron Rosenberg discovered a bug in the way Mozilla displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges.
(CAN-2005-1153)

A bug was found in the way Mozilla handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. (CAN-2005-1154)

Michael Krax discovered a bug in the way Mozilla handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges.
(CAN-2005-1155)

Michael Krax discovered a bug in the way Mozilla installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and stealm sensitive
information. (CAN-2005-1156 CAN-2005-1157)

A bug was found in the way Mozilla validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Mozilla privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. (CAN-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-26" />
        <updated date="2005-04-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1153.html">CVE-2005-1153</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1154.html">CVE-2005-1154</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1155.html">CVE-2005-1155</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1156.html">CVE-2005-1156</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1157.html">CVE-2005-1157</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
                <bugzilla href="http://bugzilla.redhat.com/155116" id="155116">CAN-2005-0989 Multiple Mozilla issues. (CAN-2005-1153  CAN-2005-1154  CAN-2005-1155  CAN-2005-1156  CAN-2005-1157  CAN-2005-1159  CAN-2005-1160)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386018" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386014" comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386016" comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386010" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386002" comment="mozilla is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386020" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386006" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386004" comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386012" comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386008" comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386022" comment="devhelp is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050386024" comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050387" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:387: cvs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:387-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-387.html" />
          <reference source="CVE" ref_id="CVE-2005-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0753.html" />
    
    <description>CVS (Concurrent Version System) is a version control system.

A buffer overflow bug was found in the way the CVS client processes version
and author information. If a user can be tricked into connecting to a
malicious CVS server, an attacker could execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0753 to this issue.

Additionally, a bug was found in which CVS freed an invalid pointer.
However, this issue does not appear to be exploitable.

All users of cvs should upgrade to this updated package, which includes a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-25" />
        <updated date="2005-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0753.html">CVE-2005-0753</cve>
                <bugzilla href="http://bugzilla.redhat.com/155029" id="155029">CAN-2005-0753 multiple issues in cvs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387002" comment="cvs is earlier than 0:1.11.2-27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387005" comment="cvs is earlier than 0:1.11.17-7.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050392" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:392: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:392-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-392.html" />
          <reference source="CVE" ref_id="CVE-2005-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0755.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes RAM files.
An attacker could create a specially crafted RAM file which could execute
arbitrary code when opened by a user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0755 to
this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.4 and is not vulnerable to this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-20" />
        <updated date="2005-04-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0755.html">CVE-2005-0755</cve>
                <bugzilla href="http://bugzilla.redhat.com/155386" id="155386">CAN-2005-0755 HelixPlayer buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050392002" comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050393" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:393: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:393-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-393.html" />
          <reference source="CVE" ref_id="CVE-2005-1046" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1046.html" />
    
    <description>KDE is a graphical desktop environment for the X Window System. Konqueror
is the file manager for the K Desktop Environment. 

A source code audit performed by the KDE security team discovered several
vulnerabilities in the PCX and other image file format readers.

A buffer overflow was found in the kimgio library for KDE 3.4.0.  An
attacker could create a carefully crafted PCX image in such a way that it
would cause kimgio to execute arbitrary code when processing the image. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1046 to this issue.

All users of kdelibs should upgrade to these updated packages, which
contain a backported security patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1046.html">CVE-2005-1046</cve>
                <bugzilla href="http://bugzilla.redhat.com/152092" id="152092">CAN-2005-1046 PCX file integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393002" comment="kdelibs is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050393004" comment="kdelibs-devel is earlier than 6:3.3.1-3.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050395" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:395: net-snmp security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-395.html" />
          <reference source="CVE" ref_id="CVE-2005-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1740.html" />
          <reference source="CVE" ref_id="CVE-2005-2177" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2177.html" />
          <reference source="CVE" ref_id="CVE-2005-4837" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4837.html" />
    
    <description>SNMP (Simple Network Management Protocol) is a protocol used for network
management. 

A denial of service bug was found in the way net-snmp uses network stream
protocols. It is possible for a remote attacker to send a net-snmp agent a
specially crafted packet that will crash the agent. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2177 to this issue.

An insecure temporary file usage bug was found in net-snmp's fixproc
command. It is possible for a local user to modify the content of temporary
files used by fixproc that can lead to arbitrary command execution. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1740 to this issue.

Additionally, the following bugs have been fixed:
- The lmSensors are correctly recognized, snmp deamon no longer segfaults
- The larger swap partition sizes are correctly reported 
- Querying hrSWInstalledLastUpdateTime no longer crashes the snmp deamon
- Fixed error building ASN.1 representation
- The 64-bit network counters correctly wrap
- Large file systems are correctly handled
- Snmptrapd initscript correctly reads options from its configuration 
  file /etc/snmp/snmptrapd.options 
- Snmp deamon no longer crashes when restarted using the agentX 
  protocol
- snmp daemon now reports gigabit Ethernet speeds correctly
- MAC adresses are shown when requested instead of IP adresses

All users of net-snmp should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1740.html">CVE-2005-1740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2177.html">CVE-2005-2177</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4837.html">CVE-2005-4837</cve>
                <bugzilla href="http://bugzilla.redhat.com/150084" id="150084">snmpd dies when getting enterprises.ucdavis.memory.memTotalSwap.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150199" id="150199">snmpd exits without a diagnostic: SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154455" id="154455">64bit network counters peg instead of wrapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154798" id="154798">/etc/init.d/snmptrapd wrong order in setting variables...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155038" id="155038">x86_64: net-snmp dies when querying hrSWInstalledLastUpdateTime</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158769" id="158769">CAN-2005-1740 net-snmp insecure temporary file usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163688" id="163688">CAN-2005-2177 net-snmp denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395004" comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373005" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395010" comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373011" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395008" comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373009" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395006" comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373007" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050395002" comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050373003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050396" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:396: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:396-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-396.html" />
          <reference source="CVE" ref_id="CVE-2005-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2495.html" />
    
    <description>X.org is an open source implementation of the X Window System. It
provides the basic low-level functionality that full-fledged graphical
user interfaces (GUIs) such as GNOME and KDE are designed upon.

Several integer overflow bugs were found in the way X.org parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue. 

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-13" />
        <updated date="2005-09-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2495.html">CVE-2005-2495</cve>
                <bugzilla href="http://bugzilla.redhat.com/166856" id="166856">CAN-2005-2495 multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396014" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198015" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396006" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198007" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396034" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198021" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198037" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396022" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198025" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396016" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198017" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396010" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198011" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396020" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198023" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396028" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198031" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396018" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198019" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396032" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198035" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396024" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198027" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396012" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198013" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396008" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198009" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396030" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198033" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396026" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198029" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050396004" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050198005" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050397" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:397: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-397.html" />
          <reference source="CVE" ref_id="CVE-2005-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0102.html" />
          <reference source="CVE" ref_id="CVE-2005-0806" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0806.html" />
    
    <description>Evolution is a GNOME-based collection of personal information management
(PIM) tools.

A bug was found in the way Evolution displays mail messages. It is possible
that an attacker could create a specially crafted mail message that when
opened by a victim causes Evolution to stop responding. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0806 to this issue.

A bug was also found in Evolution's helper program camel-lock-helper. This
bug could allow a local attacker to gain root privileges if
camel-lock-helper has been built to execute with elevated privileges.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0102 to this issue.  On Red Hat Enterprise Linux,
camel-lock-helper is not built to execute with elevated privileges by
default.  Please note however that if users have rebuilt Evolution from the
source RPM, as the root user, camel-lock-helper may be given elevated
privileges.

All users of evolution should upgrade to these updated packages, which
include backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0102.html">CVE-2005-0102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0806.html">CVE-2005-0806</cve>
                <bugzilla href="http://bugzilla.redhat.com/155375" id="155375">CAN-2005-0102 Integer overflow in camel-lock-helper</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155377" id="155377">CAN-2005-0806 DoS from mail message</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397002" comment="evolution is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050397004" comment="evolution-devel is earlier than 0:2.0.2-16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050238005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050405" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:405: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:405-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-405.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way that it could execute arbitrary instructions when processed by PHP.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
 to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- The security fixes in RHSA-2004-687 to the "unserializer" code introduced
some performance issues.

- In the gd extension, the "imagecopymerge" function did not correctly
handle transparency.  The original image was being obscured in the
resultant image.

- In the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-28" />
        <updated date="2005-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/145436" id="145436">PHP pages slow, HTTPD eating cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147808" id="147808">php curl open_basedir bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149873" id="149873">make PHP oci8 driver support Oracle Instant Client RPM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149946" id="149946">PHP GD ImageCopyMerge broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405014" comment="php-odbc is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405010" comment="php-mysql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405002" comment="php is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405012" comment="php-pgsql is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405004" comment="php-devel is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405006" comment="php-imap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050405008" comment="php-ldap is earlier than 0:4.3.2-23.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050406" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:406: PHP security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-406.html" />
          <reference source="CVE" ref_id="CVE-2004-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1392.html" />
          <reference source="CVE" ref_id="CVE-2005-0524" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0524.html" />
          <reference source="CVE" ref_id="CVE-2005-0525" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0525.html" />
          <reference source="CVE" ref_id="CVE-2005-1042" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1042.html" />
          <reference source="CVE" ref_id="CVE-2005-1043" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1043.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was found in the way PHP processes IFF and JPEG images. It is
possible to cause PHP to consume CPU resources for a short period of time
by supplying a carefully crafted IFF or JPEG image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-0524 and CAN-2005-0525 to these issues.

A buffer overflow bug was also found in the way PHP processes EXIF image
headers. It is possible for an attacker to construct an image file in such
a way it could execute arbitrary instructions when processed by PHP. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1042 to this issue.

A denial of service bug was found in the way PHP processes EXIF image
headers. It is possible for an attacker to cause PHP to enter an infinite
loop for a short period of time by supplying a carefully crafted image file
to PHP for processing. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1043 to this issue.

Several bug fixes are also included in this update:

- some performance issues in the unserialize() function have been fixed

- the behaviour of the interpreter when handling integer overflow during
conversion of a floating variable to an integer has been reverted to match
the behaviour used upstream; the integer will now be wrapped rather than
truncated

- a fix for the virtual() function in the Apache httpd module which would
flush the response prematurely

- the hard-coded default "safe mode" setting is now "disabled" rather than
"enabled"; to match the default /etc/php.ini setting

- in the curl extension, safe mode was not enforced for 'file:///' URL
lookups (CAN-2004-1392).

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-04" />
        <updated date="2005-05-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1392.html">CVE-2004-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0524.html">CVE-2005-0524</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0525.html">CVE-2005-0525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1042.html">CVE-2005-1042</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1043.html">CVE-2005-1043</cve>
                <bugzilla href="http://bugzilla.redhat.com/153108" id="153108">Error in configure prevents php SRPM rebuild on x86_64 w/ mssql module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153140" id="153140">CAN-2005-0524 PHP getimagesize() Multiple Denial of Service Vulnerabilities CAN-2005-0525</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154021" id="154021">CAN-2005-1042 PHP exif buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154025" id="154025">CAN-2005-1043 PHP exif infinite stack recursion</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406028" comment="php-gd is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406016" comment="php-odbc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406012" comment="php-mysql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406002" comment="php is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406022" comment="php-xmlrpc is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406024" comment="php-mbstring is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406014" comment="php-pgsql is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406004" comment="php-devel is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406026" comment="php-ncurses is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406018" comment="php-snmp is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406008" comment="php-imap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406006" comment="php-pear is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406020" comment="php-domxml is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050406010" comment="php-ldap is earlier than 0:4.3.9-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050408" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:408: cyrus-imapd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:408-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-408.html" />
          <reference source="CVE" ref_id="CVE-2005-0546" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0546.html" />
    
    <description>The cyrus-imapd package contains the core of the Cyrus IMAP server.

Several buffer overflow bugs were found in cyrus-imapd. It is possible that
an authenticated malicious user could cause the imap server to crash.
Additionally, a peer news admin could potentially execute arbitrary code on
the imap server when news is received using the fetchnews command. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages, which
contain cyrus-imapd version 2.2.12 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-17" />
        <updated date="2005-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0546.html">CVE-2005-0546</cve>
                <bugzilla href="http://bugzilla.redhat.com/149869" id="149869">CAN-2005-0546 multiple buffer overflows in cyrus-imapd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408006" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408007" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408004" comment="cyrus-imapd-murder is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408005" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408002" comment="cyrus-imapd is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408003" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408012" comment="cyrus-imapd-utils is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408013" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408008" comment="cyrus-imapd-devel is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408009" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050408010" comment="perl-Cyrus is earlier than 0:2.2.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050408011" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050410" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:410: gftp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-410.html" />
          <reference source="CVE" ref_id="CVE-2005-0372" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0372.html" />
    
    <description>gFTP is a multi-threaded FTP client for the X Window System.

A directory traversal bug was found in gFTP. If a user can be tricked into
downloading a file from a malicious ftp server, it is possible to overwrite
arbitrary files owned by the victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0372 to
this issue.

Users of gftp should upgrade to this updated package, which contains a
backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0372.html">CVE-2005-0372</cve>
                <bugzilla href="http://bugzilla.redhat.com/149109" id="149109">CAN-2005-0372 directory traversal issue in gftp</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410002" comment="gftp is earlier than 1:2.0.14-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410005" comment="gftp is earlier than 1:2.0.17-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050410003" comment="gftp is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050412" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:412: openmotif security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:412-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-412.html" />
          <reference source="CVE" ref_id="CVE-2005-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0605.html" />
    
    <description>OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.  

An integer overflow flaw was found in libXpm, which is used to decode XPM
(X PixMap) images.  A vulnerable version of this library was
found within OpenMotif.  An attacker could create a carefully crafted XPM
file which would cause an application to crash or potentially execute
arbitrary code if opened by a victim.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0605 to
this issue.

Users of OpenMotif are advised to upgrade to these erratum packages, which
contains a backported security patch to the embedded libXpm library.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0605.html">CVE-2005-0605</cve>
                <bugzilla href="http://bugzilla.redhat.com/151641" id="151641">CAN-2005-0605 libxpm issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412002" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412003" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412006" comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412007" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412004" comment="openmotif is earlier than 0:2.2.3-5.RHEL3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412005" comment="openmotif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412009" comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412003" comment="openmotif21 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412011" comment="openmotif-devel is earlier than 0:2.2.3-9.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412007" comment="openmotif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050412010" comment="openmotif is earlier than 0:2.2.3-9.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050412005" comment="openmotif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050413" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:413: ImageMagick security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-413.html" />
          <reference source="CVE" ref_id="CVE-2005-1275" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1275.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System which can read and write multiple image formats.

A heap based buffer overflow bug was found in the way ImageMagick parses
PNM files. An attacker could execute arbitrary code on a victim's machine
if they were able to trick the victim into opening a specially crafted PNM
file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1275 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-25" />
        <updated date="2005-05-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1275.html">CVE-2005-1275</cve>
                <bugzilla href="http://bugzilla.redhat.com/155953" id="155953">CAN-2005-1275 ImageMagick PNM heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413004" comment="ImageMagick-devel is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413006" comment="ImageMagick-perl is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413002" comment="ImageMagick is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413008" comment="ImageMagick-c++ is earlier than 0:5.5.6-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413017" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413014" comment="ImageMagick-devel is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413015" comment="ImageMagick-perl is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413013" comment="ImageMagick is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050413016" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050415" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:415: squid security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:415-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-415.html" />
          <reference source="CVE" ref_id="CVE-1999-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-1999-0710.html" />
          <reference source="CVE" ref_id="CVE-2005-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0626.html" />
          <reference source="CVE" ref_id="CVE-2005-0718" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0718.html" />
          <reference source="CVE" ref_id="CVE-2005-1345" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1345.html" />
          <reference source="CVE" ref_id="CVE-2005-1519" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1519.html" />
    
    <description>Squid is a full-featured Web proxy cache.  
 
A race condition bug was found in the way Squid handles the now obsolete
Set-Cookie header. It is possible that Squid can leak Set-Cookie header
information to other clients connecting to Squid. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0626 to this issue. Please note that this issue only affected Red
Hat Enterprise Linux 4. 
 
A bug was found in the way Squid handles PUT and POST requests. It is
possible for an authorised remote user to cause a failed PUT or POST
request which can cause Squid to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0718 to
this issue.
 
A bug was found in the way Squid processes errors in the access control
list. It is possible that an error in the access control list could give
users more access than intended. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1345 to this issue.
 
A bug was found in the way Squid handles access to the cachemgr.cgi script. 
It is possible for an authorised remote user to bypass access control
lists with this flaw. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-1999-0710 to this issue.
 
A bug was found in the way Squid handles DNS replies.  If the port Squid
uses for DNS requests is not protected by a firewall it is possible for a
remote attacker to spoof DNS replies, possibly redirecting a user to
spoofed or malicious content. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-1519 to this issue. 
 
Additionally this update fixes the following bugs:   
 - LDAP Authentication fails with an assertion error when using Red Hat
Enterprise Linux 4 
 
Users of Squid should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-14" />
        <updated date="2005-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-1999-0710.html">CVE-1999-0710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0626.html">CVE-2005-0626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0718.html">CVE-2005-0718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1345.html">CVE-2005-1345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1519.html">CVE-2005-1519</cve>
                <bugzilla href="http://bugzilla.redhat.com/125007" id="125007">insecure permissions for squid.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150232" id="150232">CAN-2005-0626 Cookie leak in squid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150907" id="150907">LDAP Authentication fails with an assertion error.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151412" id="151412">CAN-2005-1345 Unexpected access control results on configuration errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151423" id="151423">CAN-2005-0718 Segmentation fault on failed PUT/POST request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156161" id="156161">CVE-1999-0710 cachemgr.cgi access control bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157455" id="157455">CAN-2005-1519 DNS lookups unreliable on untrusted networks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050415002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050415005" comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050417" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:417: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:417-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-417.html" />
          <reference source="CVE" ref_id="CVE-2005-1278" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1278.html" />
          <reference source="CVE" ref_id="CVE-2005-1279" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1279.html" />
          <reference source="CVE" ref_id="CVE-2005-1280" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1280.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

The tcpdump utility can now write a file larger than 2 GB. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1278.html">CVE-2005-1278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1279.html">CVE-2005-1279</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1280.html">CVE-2005-1280</cve>
                <bugzilla href="http://bugzilla.redhat.com/147840" id="147840">tcpdump can't write to a file greater than 2G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156040" id="156040">CAN-2005-1280 Multiple DoS issues in tcpdump (CAN-2005-1279 CAN-2005-1278)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417004" comment="libpcap is earlier than 14:0.8.3-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417002" comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050417006" comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050420" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:420: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 1 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:420-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-420.html" />
          <reference source="CVE" ref_id="CVE-2005-0136" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0136.html" />
          <reference source="CVE" ref_id="CVE-2005-0209" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0209.html" />
          <reference source="CVE" ref_id="CVE-2005-0937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0937.html" />
          <reference source="CVE" ref_id="CVE-2005-1264" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1264.html" />
          <reference source="CVE" ref_id="CVE-2005-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3107.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the first regular kernel update to Red Hat Enterprise Linux 4.

A flaw affecting the auditing code was discovered.  On Itanium
architectures a local user could use this flaw to cause a denial of service
(crash).  This issue is rated as having important security impact
(CAN-2005-0136). 

A flaw was discovered in the servicing of a raw device ioctl.  A local user
who has access to raw devices could use this flaw to write to kernel memory
and cause a denial of service or potentially gain privileges.  This issue
is rated as having moderate security impact (CAN-2005-1264). 

A flaw in fragment forwarding was discovered that affected the netfilter
subsystem for certain network interface cards. A remote attacker could send
a set of bad fragments and cause a denial of service (system crash). Acenic
and SunGEM network interfaces were the only adapters affected, which are in
widespread use. (CAN-2005-0209)

A flaw in the futex functions was discovered affecting the Linux 2.6
kernel.  A local user could use this flaw to cause a denial of service
(system crash). (CAN-2005-0937)

New features introduced by this update include:
- Fixed TCP BIC congestion handling.
- Diskdump support for more controllers (megaraid, SATA)
- Device mapper multipath support
- AMD64 dual core support.
- Intel ICH7 hardware support.

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.

The following device drivers have been upgraded to new versions:
 ata_piix -------- 1.03
 bonding --------- 2.6.1
 e1000 ----------- 5.6.10.1-k2-NAPI
 e100 ------------ 3.3.6-k2-NAPI
 ibmveth --------- 1.03
 libata ---------- 1.02 to 1.10
 lpfc ------------ 0:8.0.16 to 0:8.0.16.6_x2
 megaraid_mbox --- 2.20.4.0 to 2.20.4.5
 megaraid_mm ----- 2.20.2.0-rh1 to 2.20.2.5
 sata_nv --------- 0.03 to 0.6
 sata_promise ---- 1.00 to 1.01
 sata_sil -------- 0.8
 sata_sis -------- 0.5
 sata_svw -------- 1.05
 sata_sx4 -------- 0.7
 sata_via -------- 1.0
 sata_vsc -------- 1.0
 tg3 ------------- 3.22-rh
 ipw2100 --------- 1.0.3
 ipw2200 --------- 1.0.0

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-08" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0136.html">CVE-2005-0136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0209.html">CVE-2005-0209</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0937.html">CVE-2005-0937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1264.html">CVE-2005-1264</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3107.html">CVE-2005-3107</cve>
                <bugzilla href="http://bugzilla.redhat.com/133590" id="133590">PTRACE_ATTACH race with real parent's wait calls can produced bogus wait returns</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134338" id="134338">Intolerable Disk I/O Performance under 64-bit VM: fix I/O buffers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137154" id="137154">"waitid(POSIX Interface)" cannot run properly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138563" id="138563">[PATCH] RHEL4 U1: EFI GPT: reduce alternate header probing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140083" id="140083">lx-choptp19 crashed running 2.4.21-20.EL.BZ131027.hotfixhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140383" id="140383">BLKFLSBUF ioctl can cause other reads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140472" id="140472">x86, x86_64 and IA64 scsi inquiry command hangs in wait_for_completion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141699" id="141699">FEAT: RHEL 4 U3: ia64 needs hint@pause in spinloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141983" id="141983">RHEL4 U2: DBS: quiet warning messages from cpufreq.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142167" id="142167">[RHEL4][Diskdump] smp_call_function issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142464" id="142464">[PATCH] "RPC: garbage, exit EIO" when using NFSv3 with Kerberos 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143073" id="143073">traced process cannot be killed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143472" id="143472">hugetlb mmap failed in compatibility mode in em64t</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143907" id="143907">ext2 and device dm-0 byond 2Terabyte causes /var/log/messages file size to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144741" id="144741">RHEL4 U1: ICH7 Support patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145424" id="145424">problems with ipsec from rhel3 to rhel4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146067" id="146067">[PATCH] Channel bonding driver configured in 802.3 ad mode causes kernel panic when shutdwon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146089" id="146089">20050115 ptrace/kill and ptrace/dump race fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146703" id="146703">NLM (NFSv3) problems when mounting with "sec=krb5"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146797" id="146797">SCTP memory consumption and system freezes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146911" id="146911">Thread suspension via async signal fails on rhel4-rc2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147832" id="147832">oom-killer triggered during Red Hat Cert</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150110" id="150110">chipset identifier for zx2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150151" id="150151">Lockd callbacks to NFS clients fail completely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151284" id="151284">mmap of file over NFS corrupts data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152101" id="152101">host panics when mounting nfs4 volumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152102" id="152102">host loses connection to nfs server when the server is solaris</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152557" id="152557">20050117 Oopsable NFS locking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154221" id="154221">Thread exits siliently via __RESTORE_ALL exeception for iret</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154639" id="154639">kernel thread current->mm dereference in grab_swap_token causes oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154972" id="154972">unexplained SIGSEGV death in SIGSEGV signal handler</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155283" id="155283">CAN-2005-0136 ptrace corner cases on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155765" id="155765">oops on 2.6.9-5.0.5.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156875" id="156875">libata - master supports lba48 but slave does not</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157450" id="157450">CAN-2005-1263 Linux kernel ELF core dump privilege elevation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420002" comment="kernel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420006" comment="kernel-doc is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420004" comment="kernel-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420010" comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420012" comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050420008" comment="kernel-smp is earlier than 0:2.6.9-11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050421" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:421: tcpdump security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:421-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-421.html" />
          <reference source="CVE" ref_id="CVE-2005-1278" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1278.html" />
          <reference source="CVE" ref_id="CVE-2005-1279" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1279.html" />
          <reference source="CVE" ref_id="CVE-2005-1280" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1280.html" />
    
    <description>Tcpdump is a command-line tool for monitoring network traffic.

Several denial of service bugs were found in the way tcpdump processes
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2005-1278, CAN-2005-1279, and CAN-2005-1280 to
these issues.

Additionally, the tcpdump utility can now write a file larger than 2 GB,
parse some new VLAN IDs, and parse messages on 64bit architectures. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1278.html">CVE-2005-1278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1279.html">CVE-2005-1279</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1280.html">CVE-2005-1280</cve>
                <bugzilla href="http://bugzilla.redhat.com/132781" id="132781">[RHEL3] tcpdump not decoding NFS traffic properly on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147840" id="147840">tcpdump can't write to a file greater than 2G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156040" id="156040">CAN-2005-1280 Multiple DoS issues in tcpdump (CAN-2005-1279 CAN-2005-1278)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421004" comment="libpcap is earlier than 14:0.7.2-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421002" comment="tcpdump is earlier than 14:3.7.2-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050421006" comment="arpwatch is earlier than 14:2.1a11-7.E3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050427" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:427: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-427.html" />
          <reference source="CVE" ref_id="CVE-2005-1456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1456.html" />
          <reference source="CVE" ref_id="CVE-2005-1457" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1457.html" />
          <reference source="CVE" ref_id="CVE-2005-1458" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1458.html" />
          <reference source="CVE" ref_id="CVE-2005-1459" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1459.html" />
          <reference source="CVE" ref_id="CVE-2005-1460" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1460.html" />
          <reference source="CVE" ref_id="CVE-2005-1461" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1461.html" />
          <reference source="CVE" ref_id="CVE-2005-1462" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1462.html" />
          <reference source="CVE" ref_id="CVE-2005-1463" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1463.html" />
          <reference source="CVE" ref_id="CVE-2005-1464" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1464.html" />
          <reference source="CVE" ref_id="CVE-2005-1465" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1465.html" />
          <reference source="CVE" ref_id="CVE-2005-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1466.html" />
          <reference source="CVE" ref_id="CVE-2005-1467" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1467.html" />
          <reference source="CVE" ref_id="CVE-2005-1468" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1468.html" />
          <reference source="CVE" ref_id="CVE-2005-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1469.html" />
          <reference source="CVE" ref_id="CVE-2005-1470" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1470.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-1456, CAN-2005-1457,
CAN-2005-1458, CAN-2005-1459, CAN-2005-1460, CAN-2005-1461, CAN-2005-1462,
CAN-2005-1463, CAN-2005-1464, CAN-2005-1465, CAN-2005-1466, CAN-2005-1467,
CAN-2005-1468, CAN-2005-1469, and CAN-2005-1470 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.11 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-24" />
        <updated date="2005-05-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1456.html">CVE-2005-1456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1457.html">CVE-2005-1457</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1458.html">CVE-2005-1458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1459.html">CVE-2005-1459</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1460.html">CVE-2005-1460</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1461.html">CVE-2005-1461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1462.html">CVE-2005-1462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1463.html">CVE-2005-1463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1464.html">CVE-2005-1464</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1465.html">CVE-2005-1465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1466.html">CVE-2005-1466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1467.html">CVE-2005-1467</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1468.html">CVE-2005-1468</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1469.html">CVE-2005-1469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1470.html">CVE-2005-1470</cve>
                <bugzilla href="http://bugzilla.redhat.com/156911" id="156911">multiple ethereal security issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427004" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427002" comment="ethereal is earlier than 0:0.10.11-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427008" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050427007" comment="ethereal is earlier than 0:0.10.11-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050429" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:429: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-429.html" />
          <reference source="CVE" ref_id="CVE-2005-1261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1261.html" />
          <reference source="CVE" ref_id="CVE-2005-1262" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1262.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

A stack based buffer overflow bug was found in the way gaim processes a
message containing a URL. A remote attacker could send a carefully crafted
message resulting in the execution of arbitrary code on a victim's machine.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1261 to this issue.

A bug was found in the way gaim handles malformed MSN messages. A remote
attacker could send a carefully crafted MSN message causing gaim to crash.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1262 to this issue.

Users of Gaim are advised to upgrade to this updated package which contains
backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-11" />
        <updated date="2005-05-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1261.html">CVE-2005-1261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1262.html">CVE-2005-1262</cve>
                <bugzilla href="http://bugzilla.redhat.com/157017" id="157017">CAN-2005-1261 Gaim long url buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157202" id="157202">CAN-2005-1262 Gaim MSN DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050429002" comment="gaim is earlier than 1:1.2.1-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050429005" comment="gaim is earlier than 1:1.2.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050430" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:430: gnutls security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-430.html" />
          <reference source="CVE" ref_id="CVE-2005-1431" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1431.html" />
    
    <description>The GnuTLS library implements Secure Sockets Layer (SSL v3) and Transport
Layer Security (TLS v1) protocols.

A denial of service bug was found in the GnuTLS library versions prior to
1.0.25. A remote attacker could perform a carefully crafted TLS handshake
against a service that uses the GnuTLS library causing the service to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1431 to this issue.

All users of GnuTLS are advised to upgrade to these updated packages and to
restart any services which use GnuTLS.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1431.html">CVE-2005-1431</cve>
                <bugzilla href="http://bugzilla.redhat.com/156856" id="156856">CAN-2005-1431 gnutls record packet parsing DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050430004" comment="gnutls-devel is earlier than 0:1.0.20-3.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430005" comment="gnutls-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050430002" comment="gnutls is earlier than 0:1.0.20-3.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050430003" comment="gnutls is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050433" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:433: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:433-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-433.html" />
          <reference source="CVE" ref_id="CVE-2005-1409" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1409.html" />
          <reference source="CVE" ref_id="CVE-2005-1410" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1410.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS) that supports almost all SQL constructs (including
transactions, subselects and user-defined types and functions).

The PostgreSQL community discovered two distinct errors in initial system
catalog entries that could allow authorized database users to crash the
database and possibly escalate their privileges.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2005-1409 and CAN-2005-1410 to these issues.

Although installing this update will protect new (freshly initdb'd)
database installations from these errors, administrators MUST TAKE MANUAL
ACTION to repair the errors in pre-existing databases.  The appropriate
procedures are explained at
http://www.postgresql.org/docs/8.0/static/release-7-4-8.html
for Red Hat Enterprise Linux 4 users, or
http://www.postgresql.org/docs/8.0/static/release-7-3-10.html
for Red Hat Enterprise Linux 3 users.

This update corrects several problems that might occur while trying to
upgrade a Red Hat Enterprise Linux 3 installation (containing rh-postgresql
packages) to Red Hat Enterprise Linux 4 (containing postgresql packages).
These updated packages correctly supersede the rh-postgresql packages.

The original release of Red Hat Enterprise Linux 4 failed to initialize the
database correctly if started for the first time with SELinux in
enforcement mode. This update corrects that problem.  

If you already have a nonfunctional database in place, shut down the
postgresql service if running, install this update, then do "sudo rm -rf
/var/lib/pgsql/data" before restarting the postgresql service.

This update also solves the problem that the PostgreSQL server might fail
to restart after a system reboot, due to a stale lockfile.

This update also corrects a problem with wrong error messages in libpq,
the postgresql client library.  The library would formerly report kernel
error messages incorrectly when the locale setting was not C.

This update also includes fixes for several other errors, including two
race conditions that could result in apparent data inconsistency or actual
data loss.

All users of PostgreSQL are advised to upgrade to these updated packages
and to apply the recommended manual corrections to existing databases.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1409.html">CVE-2005-1409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1410.html">CVE-2005-1410</cve>
                <bugzilla href="http://bugzilla.redhat.com/149237" id="149237">selinux &lt;&lt;EOF bug breaks PostgreSQL too</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151421" id="151421">PostgreSQL server does not start after crash because wrong PID file location</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151911" id="151911">upgrade from rhel-3 rh-postgresql to rhel-4 postgresql removes user "postgres"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156726" id="156726">CAN-2005-1409 Multiple postgresql issues (CAN-2005-1410)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433020" comment="rh-postgresql-jdbc is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141021" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433008" comment="rh-postgresql-docs is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433010" comment="rh-postgresql-contrib is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433002" comment="rh-postgresql is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433018" comment="rh-postgresql-python is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433014" comment="rh-postgresql-pl is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433012" comment="rh-postgresql-devel is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433022" comment="rh-postgresql-test is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433016" comment="rh-postgresql-tcl is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141017" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433006" comment="rh-postgresql-server is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141007" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433004" comment="rh-postgresql-libs is earlier than 0:7.3.10-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050141005" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433043" comment="postgresql-jdbc is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138021" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433031" comment="postgresql-docs is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138009" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433035" comment="postgresql-devel is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138013" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433045" comment="postgresql-test is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138023" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433033" comment="postgresql-contrib is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138011" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433027" comment="postgresql-libs is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138005" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433039" comment="postgresql-tcl is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138017" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433025" comment="postgresql is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138003" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433041" comment="postgresql-python is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138019" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433037" comment="postgresql-pl is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138015" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050433029" comment="postgresql-server is earlier than 0:7.4.8-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050138007" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050434" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:434: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-434.html" />
          <reference source="CVE" ref_id="CVE-2005-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1476.html" />
          <reference source="CVE" ref_id="CVE-2005-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1477.html" />
          <reference source="CVE" ref_id="CVE-2005-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1531.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several bugs were found in the way Firefox executes javascript code.
Javascript executed from a web page should run with a restricted access
level, preventing dangerous actions. It is possible that a malicious web
page could execute javascript code with elevated privileges, allowing
access to protected data and functions. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-1476,
CAN-2005-1477, CAN-2005-1531, and CAN-2005-1532 to these issues.

Please note that the effects of CAN-2005-1477 are mitigated by the default
setup, which allows only the Mozilla Update site to attempt installation of
Firefox extensions. The Mozilla Update site has been modified to prevent
this attack from working. If other URLs have been manually added to the
whitelist, it may be possible to execute this attack.

Users of Firefox are advised to upgrade to this updated package which
contains Firefox version 1.0.4 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-23" />
        <updated date="2005-05-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1476.html">CVE-2005-1476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1477.html">CVE-2005-1477</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1531.html">CVE-2005-1531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
                <bugzilla href="http://bugzilla.redhat.com/157347" id="157347">CAN-2005-1476 Multiple Firefox issues (CAN-2005-1477 CAN-2005-1531 CAN-2005-1532)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050434002" comment="firefox is earlier than 0:1.0.4-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050435" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:435: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:435-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-435.html" />
          <reference source="CVE" ref_id="CVE-2005-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1476.html" />
          <reference source="CVE" ref_id="CVE-2005-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1477.html" />
          <reference source="CVE" ref_id="CVE-2005-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1531.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Several bugs were found in the way Mozilla executes javascript code.
Javascript executed from a web page should run with a restricted access
level, preventing dangerous actions. It is possible that a malicious web
page could execute javascript code with elevated privileges, allowing
access to protected data and functions. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-1476,
CAN-2005-1477, CAN-2005-1531, and CAN-2005-1532 to these issues.

Users of Mozilla are advised to upgrade to this updated package, which
contains Mozilla version 1.7.8 to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-24" />
        <updated date="2005-05-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1476.html">CVE-2005-1476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1477.html">CVE-2005-1477</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1531.html">CVE-2005-1531</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
                <bugzilla href="http://bugzilla.redhat.com/157349" id="157349">CAN-2005-1476 Multiple Mozilla issues (CAN-2005-1477 CAN-2005-1531 CAN-2005-1532)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158533" id="158533">devhelp not updated for new mozilla</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435010" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435012" comment="mozilla-mail is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435004" comment="mozilla-chat is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435020" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435002" comment="mozilla is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435016" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435014" comment="mozilla-nspr is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435008" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435006" comment="mozilla-devel is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435018" comment="mozilla-nss is earlier than 37:1.7.8-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435027" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435028" comment="mozilla-mail is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435024" comment="mozilla-chat is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435032" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435023" comment="mozilla is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435030" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435029" comment="mozilla-nspr is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435026" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435025" comment="mozilla-devel is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435031" comment="mozilla-nss is earlier than 37:1.7.8-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435033" comment="devhelp is earlier than 0:0.9.2-2.4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050435035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050472" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:472: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-472.html" />
          <reference source="CVE" ref_id="CVE-2004-0491" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0491.html" />
          <reference source="CVE" ref_id="CVE-2005-0176" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0176.html" />
          <reference source="CVE" ref_id="CVE-2005-1263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1263.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the three security issues
described below as well as an important fix for a problem that could
lead to data corruption on x86-architecture SMP systems with greater
than 4GB of memory through heavy usage of multi-threaded applications.

A flaw between execve() syscall handling and core dumping of ELF-format
executables allowed local unprivileged users to cause a denial of
service (system crash) or possibly gain privileges.  The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-1263
to this issue.

A flaw in shared memory locking allowed local unprivileged users to lock
and unlock regions of shared memory segments they did not own (CAN-2005-0176).

A flaw in the locking of SysV IPC shared memory regions allowed local
unprivileged users to bypass their RLIMIT_MEMLOCK resource limit
(CAN-2004-0491).

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.

Please also consult the RHEL3 Update 5 advisory RHSA-2005:294 for the
complete list of features added and bugs fixed in U5, which was released
only a week prior to this security update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-25" />
        <updated date="2005-05-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0491.html">CVE-2004-0491</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0176.html">CVE-2005-0176</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1263.html">CVE-2005-1263</cve>
                <bugzilla href="http://bugzilla.redhat.com/126411" id="126411">CVE-2004-0491 mlock accounting issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141394" id="141394">Memory corruption with kernel 2.4.21-27.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141905" id="141905">kernel 2.4.21-25.ELsmp panic (kscand)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142802" id="142802">CVE-2005-0176 unlock someone elses ipc memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149087" id="149087">Kernel panic regression in 2.4.21-27.0.2.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151865" id="151865">Page corruption in U5 Beta</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156023" id="156023">Memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157451" id="157451">CVE-2005-1263 Linux kernel ELF core dump crash vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472004" comment="kernel-source is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472002" comment="kernel is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472006" comment="kernel-doc is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472018" comment="kernel-hugemem is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472008" comment="kernel-BOOT is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472010" comment="kernel-unsupported is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050472014" comment="kernel-smp is earlier than 0:2.4.21-32.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050474" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:474: bzip2 security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:474-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-474.html" />
          <reference source="CVE" ref_id="CVE-2005-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0758.html" />
          <reference source="CVE" ref_id="CVE-2005-0953" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0953.html" />
          <reference source="CVE" ref_id="CVE-2005-1260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1260.html" />
    
    <description>Bzip2 is a data compressor.

A bug was found in the way bzgrep processes file names. If a user can be
tricked into running bzgrep on a file with a carefully crafted file name,
arbitrary commands could be executed as the user running bzgrep. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CVE-2005-0758 to this issue.

A bug was found in the way bzip2 modifies file permissions during
decompression. If an attacker has write access to the directory into which
bzip2 is decompressing files, it is possible for them to modify permissions
on files owned by the user running bzip2 (CVE-2005-0953).

A bug was found in the way bzip2 decompresses files. It is possible for an
attacker to create a specially crafted bzip2 file which will cause bzip2 to
cause a denial of service (by filling disk space) if decompressed by a
victim (CVE-2005-1260).

Users of Bzip2 should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-06-16" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0758.html">CVE-2005-0758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0953.html">CVE-2005-0953</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1260.html">CVE-2005-1260</cve>
                <bugzilla href="http://bugzilla.redhat.com/155742" id="155742">CAN-2005-0953 bzip2 race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157548" id="157548">CAN-2005-1260 bzip2 decompression bomb (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159816" id="159816">CVE-2005-0758 bzgrep has security issue in sed usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474004" comment="bzip2-devel is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474005" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474006" comment="bzip2-libs is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474007" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474002" comment="bzip2 is earlier than 0:1.0.2-11.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474003" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474010" comment="bzip2-devel is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474005" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474011" comment="bzip2-libs is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474007" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050474009" comment="bzip2 is earlier than 0:1.0.2-13.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050474003" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050476" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:476: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:476-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-476.html" />
          <reference source="CVE" ref_id="CVE-2004-0975" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0975.html" />
          <reference source="CVE" ref_id="CVE-2005-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0109.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

Colin Percival reported a cache timing attack that could allow a malicious
local user to gain portions of cryptographic keys.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) assigned the name
CAN-2005-0109 to the issue.  The OpenSSL library has been patched to add a
new fixed-window mod_exp implementation as default for RSA, DSA, and DH
private-key operations.  This patch is designed to mitigate cache timing
and potentially related attacks.

A flaw was found in the way the der_chop script creates temporary files. It
is possible that a malicious local user could cause der_chop to overwrite
files (CAN-2004-0975).  The der_chop script was deprecated and has been
removed from these updated packages.  Red Hat Enterprise Linux 4 did not
ship der_chop and is therefore not vulnerable to this issue.

Users are advised to update to these erratum packages which contain patches
to correct these issues.

Please note: After installing this update, users are advised to either
restart all services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-01" />
        <updated date="2005-06-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0975.html">CVE-2004-0975</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0109.html">CVE-2005-0109</cve>
                <bugzilla href="http://bugzilla.redhat.com/136302" id="136302">CAN-2004-0975 temporary file vulnerabilities in der_chop script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140061" id="140061">CAN-2004-0975 temporary file vulnerabilities in der_chop script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157631" id="157631">CAN-2005-0109 timing attack on OpenSSL with HT</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476002" comment="openssl096b is earlier than 0:0.9.6b-16.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476004" comment="openssl is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476005" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476008" comment="openssl-perl is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476009" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476006" comment="openssl-devel is earlier than 0:0.9.7a-33.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476007" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476011" comment="openssl096b is earlier than 0:0.9.6b-22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476012" comment="openssl is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476005" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476014" comment="openssl-perl is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476009" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050476013" comment="openssl-devel is earlier than 0:0.9.7a-43.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476007" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050480" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:480: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-480.html" />
          <reference source="CVE" ref_id="CVE-2005-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1739.html" />
    
    <description>ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

A denial of service bug was found in the way ImageMagick parses XWD files.
A user or program executing ImageMagick to process a malicious XWD file can
cause ImageMagick to enter an infinite loop causing a denial of service
condition. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-1739 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-02" />
        <updated date="2005-06-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1739.html">CVE-2005-1739</cve>
                <bugzilla href="http://bugzilla.redhat.com/158790" id="158790">CAN-2005-1739 ImageMagick XWD denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480010" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480004" comment="ImageMagick-devel is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480006" comment="ImageMagick-perl is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480002" comment="ImageMagick is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480008" comment="ImageMagick-c++ is earlier than 0:5.5.6-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480017" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480014" comment="ImageMagick-devel is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480015" comment="ImageMagick-perl is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480013" comment="ImageMagick is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050480016" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050498" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:498: spamassassin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:498-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-498.html" />
          <reference source="CVE" ref_id="CVE-2005-1266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1266.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (SPAM)
from incoming email.

A denial of service bug has been found in SpamAssassin.  An attacker could
construct a message in such a way that would cause SpamAssassin to consume
CPU resources.  If a number of these messages were sent it could lead to a
denial of service, potentially  preventing the delivery or filtering of
email. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1266 to this issue.

SpamAssassin version 3.0.4 additionally solves a number of bugs including:
- #156390 Spamassassin consumes too much memory during learning
- #155423 URI blacklist spam bypass
- #147464 Users may now disable subject rewriting
- Smarter default Bayes scores
- Numerous other bug fixes that improve spam filter accuracy and safety

For full details, please refer to the change details of 3.0.2, 3.0.3, and
3.0.4 in SpamAssassin's online documentation at the following address:
http://wiki.apache.org/spamassassin/NextRelease

Users of SpamAssassin should update to this updated package, containing
version 3.0.4 which is not vulnerable to this issue and resolves these bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1266.html">CVE-2005-1266</cve>
                <bugzilla href="http://bugzilla.redhat.com/147464" id="147464">spamassassin no longer allows disabling subject rewriting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151433" id="151433">spamd generate child processes which occupies all memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159198" id="159198">CAN-2005-1266 spamassassin DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050498002" comment="spamassassin is earlier than 0:3.0.4-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050498003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050499" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:499: gedit security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:499-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-499.html" />
          <reference source="CVE" ref_id="CVE-2005-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1686.html" />
    
    <description>gEdit is a small text editor designed specifically for the GNOME GUI desktop. 

A file name format string vulnerability has been discovered in gEdit. It is
possible for an attacker to create a file with a carefully crafted name
which, when the file is opened, executes arbitrary instructions on a
victim's machine. Although it is unlikely that a user would manually open a
file with such a carefully crafted file name, a user could, for example, be
tricked into opening such a file from within an email client.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1686 to this issue. 

Users of gEdit should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1686.html">CVE-2005-1686</cve>
                <bugzilla href="http://bugzilla.redhat.com/159655" id="159655">CAN-2005-1686 filename format string vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499002" comment="gedit is earlier than 1:2.2.2-4.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499003" comment="gedit is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050499006" comment="gedit-devel is earlier than 1:2.8.1-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499007" comment="gedit-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050499005" comment="gedit is earlier than 1:2.8.1-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050499003" comment="gedit is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050501" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:501: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:501-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-501.html" />
          <reference source="CVE" ref_id="CVE-2005-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2495.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides
the core functionality for the Linux graphical desktop.

Several integer overflow bugs were found in the way XFree86 parses pixmap
images. It is possible for a user to gain elevated privileges by loading a
specially crafted pixmap image. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2495 to this issue.

Additionally this update adds the following new features in this release:
- Support for ATI RN50/ES1000 chipsets has been added.

The following bugs were also fixed in this release:
- A problem with the X server's module loading system that led to cache
  incoherency on the Itanium architecture.

- The X server's PCI config space accesses caused contention
  with the kernel if accesses occurred while the kernel lock was held.

- X font server (xfs) crashed when accessing Type 1 fonts
  via showfont.

- A problem with the X transport library prevented X applications
  from starting if the hostname started with a digit.

- An issue where refresh rates were being restricted to 60Hz on
  some Intel i8xx systems

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-15" />
        <updated date="2005-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2495.html">CVE-2005-2495</cve>
                <bugzilla href="http://bugzilla.redhat.com/116040" id="116040">no refresh > 60 Hz for i810</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134883" id="134883">(xtrans bug) Can't open display: 50dhcp26:0.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135606" id="135606">X Font Server crashes when accessing Type 1 fonts via showfont.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153106" id="153106">ia64 elfloader cache flush</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166857" id="166857">CAN-2005-2495 multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501042" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331043" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501012" comment="XFree86-xdm is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331013" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501032" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331033" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501028" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331029" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501016" comment="XFree86-libs-data is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331017" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501046" comment="XFree86-doc is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331047" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501044" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331045" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501030" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331031" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501002" comment="XFree86 is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331057" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501020" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331021" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501014" comment="XFree86-libs is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331015" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501060" comment="XFree86-sdk is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331061" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501024" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331025" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501008" comment="XFree86-xfs is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331009" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501048" comment="XFree86-Xnest is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331049" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331037" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501022" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331023" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501040" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331041" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501034" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331035" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501058" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331059" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501026" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331027" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501038" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331039" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501018" comment="XFree86-base-fonts is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331019" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501006" comment="XFree86-font-utils is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331007" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501052" comment="XFree86-tools is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331053" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501050" comment="XFree86-Xvfb is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331051" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501010" comment="XFree86-twm is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331011" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501054" comment="XFree86-xauth is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331055" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050501004" comment="XFree86-devel is earlier than 0:4.3.0-95.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050331005" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050502" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:502: sysreport security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:502-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-502.html" />
          <reference source="CVE" ref_id="CVE-2005-1760" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1760.html" />
    
    <description>Sysreport is a utility that gathers information about a system's hardware
and configuration. The information can then be used for diagnostic purposes
and debugging.

When run by the root user, sysreport includes the contents of the
/etc/sysconfig/rhn/up2date configuration file.  If up2date has been
configured to connect to a proxy server that requires an authentication
password, that password is included in plain text in the system report. 
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1760 to this issue.

Users of sysreport should update to this erratum package, which contains a
patch that removes any proxy authentication passwords.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1760.html">CVE-2005-1760</cve>
                <bugzilla href="http://bugzilla.redhat.com/159502" id="159502">CAN-2005-1760 sysreport includes proxy password in cleartext</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502002" comment="sysreport is earlier than 0:1.3.7.2-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502005" comment="sysreport is earlier than 0:1.3.15-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050504" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:504: telnet security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:504-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-504.html" />
          <reference source="CVE" ref_id="CVE-2005-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0488.html" />
    
    <description>The telnet package provides a command line telnet client. 

Gaël Delalleau discovered an information disclosure issue in the way the
telnet client handles messages from a server.  An attacker could construct
a malicious telnet server that collects information from the environment of
any victim who connects to it.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0488 to this issue.

Users of telnet should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-06-14" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0488.html">CVE-2005-0488</cve>
                <bugzilla href="http://bugzilla.redhat.com/159297" id="159297">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504002" comment="telnet is earlier than 1:0.17-26.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504004" comment="telnet-server is earlier than 1:0.17-26.EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504007" comment="telnet is earlier than 1:0.17-31.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327003" comment="telnet is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050504008" comment="telnet-server is earlier than 1:0.17-31.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050327005" comment="telnet-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050505" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:505: tcpdump security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:505-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-505.html" />
          <reference source="CVE" ref_id="CVE-2005-1267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1267.html" />
    
    <description>Tcpdump is a command line tool for monitoring network traffic.

A denial of service bug was found in tcpdump during the processing of
certain network packets. It is possible for an attacker to inject a
carefully crafted packet onto the network, crashing a running tcpdump
session. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CAN-2005-1267 to this issue. 

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1267.html">CVE-2005-1267</cve>
                <bugzilla href="http://bugzilla.redhat.com/159208" id="159208">CAN-2005-1267 tcpdump BGP DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505004" comment="libpcap is earlier than 14:0.8.3-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417005" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505002" comment="tcpdump is earlier than 14:3.8.2-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050505006" comment="arpwatch is earlier than 14:2.1a13-10.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050417007" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050506" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:506: mikmod security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-506.html" />
          <reference source="CVE" ref_id="CVE-2003-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0427.html" />
    
    <description>MikMod is a well known MOD music file player for UNIX-based systems.

A buffer overflow bug was found in mikmod during the processing of archive
filenames. An attacker could create a malicious archive that when opened by
mikmod could result in arbitrary code execution. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0427
to this issue. 

Users of mikmod are advised to upgrade to these erratum packages, which
contain backported security patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-13" />
        <updated date="2005-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0427.html">CVE-2003-0427</cve>
                <bugzilla href="http://bugzilla.redhat.com/159290" id="159290">CAN-2003-0427 mikmod flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506002" comment="mikmod is earlier than 0:3.1.6-22.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506003" comment="mikmod is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506004" comment="mikmod-devel is earlier than 0:3.1.6-22.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506005" comment="mikmod-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506007" comment="mikmod is earlier than 0:3.1.6-32.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506003" comment="mikmod is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050506008" comment="mikmod-devel is earlier than 0:3.1.6-32.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050506005" comment="mikmod-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050514" version="504" class="patch">
      <metadata>
        <title>RHSA-2005:514: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 2 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:514-03" ref_url="https://rhn.redhat.com/errata/RHSA-2005-514.html" />
          <reference source="CVE" ref_id="CVE-2005-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0756.html" />
          <reference source="CVE" ref_id="CVE-2005-1265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1265.html" />
          <reference source="CVE" ref_id="CVE-2005-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1761.html" />
          <reference source="CVE" ref_id="CVE-2005-1762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1762.html" />
          <reference source="CVE" ref_id="CVE-2005-1763" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1763.html" />
          <reference source="CVE" ref_id="CVE-2005-2098" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2098.html" />
          <reference source="CVE" ref_id="CVE-2005-2099" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2099.html" />
          <reference source="CVE" ref_id="CVE-2005-2100" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2100.html" />
          <reference source="CVE" ref_id="CVE-2005-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2456.html" />
          <reference source="CVE" ref_id="CVE-2005-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2490.html" />
          <reference source="CVE" ref_id="CVE-2005-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2492.html" />
          <reference source="CVE" ref_id="CVE-2005-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2555.html" />
          <reference source="CVE" ref_id="CVE-2005-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2801.html" />
          <reference source="CVE" ref_id="CVE-2005-2872" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2872.html" />
          <reference source="CVE" ref_id="CVE-2005-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3105.html" />
          <reference source="CVE" ref_id="CVE-2005-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3274.html" />
          <reference source="CVE" ref_id="CVE-2005-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3275.html" />
          <reference source="CVE" ref_id="CVE-2005-4886" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4886.html" />
          <reference source="CVE" ref_id="CVE-2006-5871" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5871.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the second regular kernel update to Red Hat Enterprise Linux 4.

New features introduced in this update include:
- Audit support
- systemtap - kprobes, relayfs
- Keyring support
- iSCSI Initiator - iscsi_sfnet 4:0.1.11-1
- Device mapper multipath support
- Intel dual core support
- esb2 chipset support
- Increased exec-shield coverage
- Dirty page tracking for HA systems
- Diskdump -- allow partial diskdumps and directing to swap

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4. 

The following security bugs were fixed in this update, detailed below with
corresponding CAN names available from the Common Vulnerabilities and
Exposures project (cve.mitre.org):

- flaws in ptrace() syscall handling on 64-bit systems that allowed a local
user to cause a denial of service (crash) (CAN-2005-0756, CAN-2005-1761,
CAN-2005-1762, CAN-2005-1763)

- flaws in IPSEC network handling that allowed a local user to cause a
denial of service or potentially gain privileges (CAN-2005-2456, CAN-2005-2555)

- a flaw in sendmsg() syscall handling on 64-bit systems that allowed a
local user to cause a denial of service or potentially gain privileges
(CAN-2005-2490)

- a flaw in sendmsg() syscall handling that allowed a local user to cause a
denial of service by altering hardware state (CAN-2005-2492)

- a flaw that prevented the topdown allocator from allocating mmap areas
all the way down to address zero (CAN-2005-1265)

- flaws dealing with keyrings that could cause a local denial of service
(CAN-2005-2098, CAN-2005-2099)

- a flaw in the 4GB split patch that could allow a local denial of service
(CAN-2005-2100)

- a xattr sharing bug in the ext2 and ext3 file systems that could cause
default ACLs to disappear (CAN-2005-2801)

- a flaw in the ipt_recent module on 64-bit architectures which could allow
a remote denial of service (CAN-2005-2872)

The following device drivers have been upgraded to new versions:

qla2100 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2200 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2300 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2322 --------- 8.00.00b21-k to 8.01.00b5-rh2
qla2xxx --------- 8.00.00b21-k to 8.01.00b5-rh2
qla6312 --------- 8.00.00b21-k to 8.01.00b5-rh2
megaraid_mbox --- 2.20.4.5 to 2.20.4.6
megaraid_mm ----- 2.20.2.5 to 2.20.2.6 
lpfc ------------ 0:8.0.16.6_x2 to 0:8.0.16.17
cciss ----------- 2.6.4 to 2.6.6
ipw2100 --------- 1.0.3 to 1.1.0
tg3 ------------- 3.22-rh to 3.27-rh
e100 ------------ 3.3.6-k2-NAPI to 3.4.8-k2-NAPI
e1000 ----------- 5.6.10.1-k2-NAPI to 6.0.54-k2-NAPI
3c59x ----------- LK1.1.19
mptbase --------- 3.01.16 to 3.02.18
ixgb ------------ 1.0.66 to 1.0.95-k2-NAPI
libata ---------- 1.10 to 1.11
sata_via -------- 1.0 to 1.1
sata_ahci ------- 1.00 to 1.01
sata_qstor ------ 0.04
sata_sil -------- 0.8 to 0.9
sata_svw -------- 1.05 to 1.06
s390: crypto ---- 1.31 to 1.57
s390: zfcp ------ 
s390: CTC-MPC ---
s390: dasd -------
s390: cio -------
s390: qeth ------

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0756.html">CVE-2005-0756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1265.html">CVE-2005-1265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1761.html">CVE-2005-1761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1762.html">CVE-2005-1762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1763.html">CVE-2005-1763</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2098.html">CVE-2005-2098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2099.html">CVE-2005-2099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2100.html">CVE-2005-2100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2456.html">CVE-2005-2456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2490.html">CVE-2005-2490</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2492.html">CVE-2005-2492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2555.html">CVE-2005-2555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2801.html">CVE-2005-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2872.html">CVE-2005-2872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3105.html">CVE-2005-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3274.html">CVE-2005-3274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3275.html">CVE-2005-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4886.html">CVE-2005-4886</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5871.html">CVE-2006-5871</cve>
                <bugzilla href="http://bugzilla.redhat.com/114578" id="114578">RHEL4 U1: File Delegation, at least read-only.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/130914" id="130914">RHEL4: keyring support (OpenAFS enabler)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134790" id="134790">Inspiron 8500 practically hangs when configuring b44 NIC with 1.5G memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135669" id="135669">tcsendbreak fails in compat mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137343" id="137343">RH40-beta1, embedded IDE/PCI drivers not honoring Sub ID's/Class code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140002" id="140002">[PATCH] i2o_block timeout Adaptec  2400A raid card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141783" id="141783">domain validation fails on DVD-305 when CD in drive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142989" id="142989">Terminated threads' resource usage is hidden from procps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144668" id="144668">System doesn't reboot even if kernel.panic is > 0 on RHEL-4 Beta-2.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145575" id="145575">[RHEL4-U2][Diskdump] Partial dump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145648" id="145648">Socket option IP_FREEBIND has no effect on SCTP socket.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145659" id="145659">Socket option SO_BINDTODEVICE problems with SCTP listening socket.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145976" id="145976">Sub-second mtime changes without modifying file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146187" id="146187">[RHEL4RC1] chicony usb keyboard fails, with side effects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147233" id="147233">NFSv3 over Kerberos: gss_get_mic FAILED during xdm login attempt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147496" id="147496">Sense data errors are seen when trying to access a travan tape device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149478" id="149478">Bug / data corruption on error handling in Ext3 under I/O failure condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149919" id="149919">highmem.c: fix bio error propagation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149979" id="149979">kernel panic when tar'ing data to IDE Tape device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150152" id="150152">nfsv4 callback authentication patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151222" id="151222">smp_apic_timer_interrupt() executes on kernel thread stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151315" id="151315">kernel BUG() at pageattr:107 with rmmod e1000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151323" id="151323">Kernel BUG at pageattr:107</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151429" id="151429">Fusion MPT doesn't handle multiple PCI domains correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152162" id="152162">LVM snapshots over md raid1 cause corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152440" id="152440">ppc64 arches can crash when single setpping a debugger through syscall return code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152619" id="152619">openipmi drivers missing compat_ioctl's on x86_64 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152982" id="152982">fail to mount nfs4 servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154055" id="154055">RHEL4 U1  Oracle 10G 10.0.3 aio hang running tpc-c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154100" id="154100">assertion failrue in semaphore.h caused by perfmon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154347" id="154347">spin_lock already locked by xfrm4_output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154435" id="154435">kernel dm-emc: Fix spinlock reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154442" id="154442">kernel dm-multipath: multiple pg_inits can be issued in parallel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154451" id="154451">CAN-2005-1762 x86_64 sysret exception leads to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154733" id="154733">oops when catting /proc/net/ip_conntrack_expect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155278" id="155278">Debugger killed by kernel when looking at the lowest addressed vmalloc page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155344" id="155344">add fix for IPMI/ACPI  OOPS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155354" id="155354">20050313 SCSI tape security</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155706" id="155706">CAN-2005-2801 xattr sharing bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155932" id="155932">[RHEL4-U2][Diskdump] hangs when SCSI drive is busy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156010" id="156010">[RHEL4-U2] Diskdump - swap partition support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156705" id="156705">Serial console corrupt on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157239" id="157239">Systemtap patches to be ported to RHEL4 U2 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157725" id="157725">sysctl -A returns an error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157900" id="157900">[not quite PATCH] tg3 driver crashes kernel with BCM5752 chip, newer driver is OK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158107" id="158107">Serial console turns into garbage after initialising 16550A</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158293" id="158293">nfs server intermitently claims ENOENT on existing files or directories</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158878" id="158878">CAN-2005-1265 Prevent NULL mmap in topdown model</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158883" id="158883">Annoying i2o_config kernel module messages during raidutil run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158930" id="158930">32-bit GETBLKSIZE ioctl overflows incorrectly on 64-bit hosts.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158974" id="158974">[Patch] modprobling a module signed with a key not known to the kernel can result in a panic.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159640" id="159640">proc and sysctl interface for lockd grace period do not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159671" id="159671">CAN-2005-1761 local user can use ptrace to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159739" id="159739">[Stratus RHEL4U2] csb5 functions are tagged with __init.  This causes a crash in a hot-plug environment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159765" id="159765">RHEL4 Data corruption in spite of using O_SYNC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159918" id="159918">CAN-2005-0756 x86_64 crash (ptrace-check-segment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159921" id="159921">CAN-2005-1763 x86_64 crash (x86_64-ptrace-overflow)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160028" id="160028">Kernel BUG at pageattr:107</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160518" id="160518">audit: file system and user space filtering by auid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160522" id="160522">audit: teach OOM killer about auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160524" id="160524">audit: file system attribute change tracking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160526" id="160526">audit:PATH record mode flags are wrong sometimes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160528" id="160528">audit: file system watch on block device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160547" id="160547">when removing scsi hosts commands are not leaked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160548" id="160548">when removing scsi hosts commands are not leaked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160654" id="160654">audit: kernel audits auditd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160663" id="160663">cable link state ignored on ethernet card (b44).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160812" id="160812">fixes exec-shield to not randomize to between end-of-binary and start-of-brk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160882" id="160882">i2o RAID monitoring memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161143" id="161143">Need export of generic_drop_inode for OCFS2 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161156" id="161156">'mt tell' fails - backported kernel bug likely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161314" id="161314">Bluetooth paring did not work anymore since update to 2.6.9-11.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161789" id="161789">GET_INDEX macro in aspm pci fixup code can overwrite end of the array</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161995" id="161995">kernel panic when rm -rf directory structure on tmpfs filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162108" id="162108">only the main thread is shown by top(1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162257" id="162257">irq stacks not being used for hardirqs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162548" id="162548">interrupt handlers run on thread's kernel stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162728" id="162728">JBD race during shutdown of a journal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163528" id="163528">/dev/tty won't open during blocking /dev/ttyS1 open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164094" id="164094">Placeholder for 2.6.x SATA update 20050724-1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164228" id="164228">Export sys_recvmesg for cluster snapshot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164338" id="164338">fix aio hang when reading beyond EOF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164449" id="164449">RHEL4 [NETFILTER]: Fix deadlock in ip6_queue.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164450" id="164450">[NETFILTER]: Fix potential memory corruption in NAT code (aka memory NAT)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164628" id="164628">pci_scan_device can cause master abort</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164630" id="164630">panic while running fsstress to a filesystem on a mirror</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164979" id="164979">CAN-2005-2098 Error during attempt to join key management session can leave semaphore pinned</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164991" id="164991">CAN-2005-2099 Destruction of failed keyring oopses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165127" id="165127">acpi_processor_get_performance_states fails on empty table entries (_PSS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165163" id="165163">audit - syscall performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165242" id="165242">mirrors possibly reporting invalid blocks to the filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165384" id="165384">cpufreq driver hangs when using SMP Powernow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165547" id="165547">CAN-2005-2100 4G/4G split bounds checking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165560" id="165560">CAN-2005-2456 IPSEC overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165717" id="165717">ext on top of mirror attempts to access beyond end of device: dm-5: rw=0, want=16304032720, limit=20971520</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166131" id="166131">CAN-2005-2555 IPSEC lacks restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166248" id="166248">CAN-2005-2490 sendmsg compat stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166830" id="166830">CAN-2005-2492 sendmsg DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167126" id="167126">bad elf check in module-verify.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167412" id="167412">[RFC] [RHEL4 U2 patch] dual-core detection gap for i386 build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167668" id="167668">LTC17960-Kernel panic at key_put+0x4/0x19 [REGRESSION]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167703" id="167703">CAN-2005-2872 ipt_recent crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167711" id="167711">LTC18014-powernow-k8 debug messages are enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514002" comment="kernel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514006" comment="kernel-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514004" comment="kernel-doc is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514010" comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514012" comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050514008" comment="kernel-smp is earlier than 0:2.6.9-22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050517" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:517: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:517-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-517.html" />
          <reference source="CVE" ref_id="CVE-2005-1766" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1766.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow bug was found in the way HelixPlayer processes SMIL files.
An attacker could create a specially crafted SMIL file, which when combined
with a malicious web server, could execute arbitrary code when opened by a
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1766 to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.5 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1766.html">CVE-2005-1766</cve>
                <bugzilla href="http://bugzilla.redhat.com/159871" id="159871">CAN-2005-1766 HelixPlayer heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050517002" comment="HelixPlayer is earlier than 1:1.0.5-0.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050518" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:518: gaim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:518-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-518.html" />
          <reference source="CVE" ref_id="CVE-2005-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1269.html" />
          <reference source="CVE" ref_id="CVE-2005-1934" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1934.html" />
    
    <description>The Gaim application is a multi-protocol instant messaging client.

Jacopo Ottaviani discovered a bug in the way Gaim handles Yahoo! Messenger
file transfers. It is possible for a malicious user to send a specially
crafted file transfer request that causes Gaim to crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1269 to this issue.

Additionally, Hugo de Bokkenrijder discovered a bug in the way Gaim parses
MSN Messenger messages. It is possible for a malicious user to send a
specially crafted MSN Messenger message that causes Gaim to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1934 to this issue.

Users of gaim are advised to upgrade to this updated package, which contains
version 1.3.1 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-16" />
        <updated date="2005-06-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1269.html">CVE-2005-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1934.html">CVE-2005-1934</cve>
                <bugzilla href="http://bugzilla.redhat.com/159691" id="159691">CAN-2005-1269 Gaim yahoo utf8 crasher</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159961" id="159961">CAN-2005-1934 Gaim MSN protocol DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050518002" comment="gaim is earlier than 1:1.3.1-0.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050518005" comment="gaim is earlier than 1:1.3.1-0.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050524" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:524: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:524-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-524.html" />
          <reference source="CVE" ref_id="CVE-2005-1454" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1454.html" />
          <reference source="CVE" ref_id="CVE-2005-1455" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1455.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A buffer overflow bug was found in the way FreeRADIUS escapes data in an
SQL query. An attacker may be able to crash FreeRADIUS if they cause
FreeRADIUS to escape a string containing three or less characters. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-1454 to this issue.

Additionally a bug was found in the way FreeRADIUS escapes SQL data. It is
possible that an authenticated user could execute arbitrary SQL queries by
sending a specially crafted request to FreeRADIUS. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1455 to this issue.

Users of FreeRADIUS should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-23" />
        <updated date="2005-06-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1454.html">CVE-2005-1454</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1455.html">CVE-2005-1455</cve>
                <bugzilla href="http://bugzilla.redhat.com/156941" id="156941">CAN-2005-1454 Multiple issues in freeradius (CAN-2005-1455)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524004" comment="freeradius-mysql is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524006" comment="freeradius-postgresql is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524008" comment="freeradius-unixODBC is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524002" comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524012" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524005" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524013" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524007" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524014" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524009" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050524011" comment="freeradius is earlier than 0:1.0.1-3.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050524003" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050527" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:527: openssh security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:527-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-527.html" />
          <reference source="CVE" ref_id="CVE-2005-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-1483" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1483.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. 

An error in the way OpenSSH handled GSSAPI credential delegation was
discovered. OpenSSH as distributed with Red Hat Enterprise Linux 4 contains
support for GSSAPI user authentication, typically used for supporting
Kerberos. On OpenSSH installations which have GSSAPI enabled, this flaw
could allow a user who sucessfully authenticates using a method other than
GSSAPI to be delegated with GSSAPI credentials. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2798
to this issue.

Additionally, the following bugs have been addressed:

The ssh command incorrectly failed when it was issued by the root user with
a non-default group set.

The sshd daemon could fail to properly close the client connection if
multiple X clients were forwarded over the connection and the client
session exited.

The sshd daemon could bind only on the IPv6 address family for X forwarding
if the port on IPv4 address family was already bound. The X forwarding did
not work in such cases.

This update also adds support for recording login user IDs for the auditing
service. The user ID is attached to the audit records generated from the
user's session.

All users of openssh should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2798.html">CVE-2005-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1483.html">CVE-2008-1483</cve>
                <bugzilla href="http://bugzilla.redhat.com/159331" id="159331">sshd update for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167444" id="167444">CAN-2005-2798 Improper GSSAPI credential delegation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527002" comment="openssh is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527010" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527004" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527006" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050527008" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050535" version="505" class="patch">
      <metadata>
        <title>RHSA-2005:535: sudo security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:535-04" ref_url="https://rhn.redhat.com/errata/RHSA-2005-535.html" />
          <reference source="CVE" ref_id="CVE-2005-1993" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1993.html" />
    
    <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A race condition bug was found in the way sudo handles pathnames. It is
possible that a local user with limited sudo access could create
a race condition that would allow the execution of arbitrary commands as
the root user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1993 to this issue.

Users of sudo should update to this updated package, which contains a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-06-29" />
        <updated date="2005-06-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1993.html">CVE-2005-1993</cve>
                <bugzilla href="http://bugzilla.redhat.com/161116" id="161116">CAN-2005-1993 sudo trusted user arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535002" comment="sudo is earlier than 0:1.6.7p5-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535003" comment="sudo is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535005" comment="sudo is earlier than 0:1.6.7p5-30.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050535003" comment="sudo is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050543" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:543: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:543-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-543.html" />
          <reference source="CVE" ref_id="CVE-2005-1992" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1992.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A bug was found in the way Ruby launched an XMLRPC server. If an XMLRPC
server is launched in a certain way, it becomes possible for a remote
attacker to execute arbitrary commands within the XMLRPC server. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1992 to this issue. 

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-05" />
        <updated date="2005-08-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1992.html">CVE-2005-1992</cve>
                <bugzilla href="http://bugzilla.redhat.com/161095" id="161095">CAN-2005-1992 ruby arbitrary command execution on XMLRPC server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543012" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543010" comment="irb is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543014" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543008" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543004" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543002" comment="ruby is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050543006" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050550" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:550: openssh security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:550-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-550.html" />
          <reference source="CVE" ref_id="CVE-2004-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2069.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
includes the core files necessary for both the OpenSSH client and server. 

A bug was found in the way the OpenSSH server handled the MaxStartups and
LoginGraceTime configuration variables. A malicious user could connect to
the SSH daemon in such a way that it would prevent additional logins from
occuring until the malicious connections are closed. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-2069 to this issue.

Additionally, the following issues are resolved with this update:

- The -q option of the ssh client did not suppress the banner message sent
by the server, which caused errors when used in scripts.

- The sshd daemon failed to close the client connection if multiple X
clients were forwarded over the connection and the client session exited.

- The sftp client leaked memory if used for extended periods.

- The sshd daemon called the PAM functions incorrectly if the user was
unknown on the system.

All users of openssh should upgrade to these updated packages, which
contain backported patches and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2069.html">CVE-2004-2069</cve>
                <bugzilla href="http://bugzilla.redhat.com/129289" id="129289">[PATCH] SSH -q flag does not suppress banner text</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151080" id="151080">sftp over a persistent connection (days/weeks) develops a memory leak.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156996" id="156996">CAN-2004-2069 openssh DoS issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550002" comment="openssh is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550010" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106011" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550004" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550006" comment="openssh-server is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050550008" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050106009" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050562" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:562: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:562-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-562.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-0488" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0488.html" />
          <reference source="CVE" ref_id="CVE-2005-1175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1175.html" />
          <reference source="CVE" ref_id="CVE-2005-1689" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1689.html" />
    
    <description>Kerberos is a networked authentication system which uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A double-free flaw was found in the krb5_recvauth() routine which may be
triggered by a remote unauthenticated attacker.  Although no exploit is
currently known to exist, this issue could potentially be exploited to
allow arbitrary code execution on a Key Distribution Center (KDC). The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1689 to this issue. 

Daniel Wachdorf discovered a single byte heap overflow in the
krb5_unparse_name() function, part of krb5-libs. Sucessful exploitation of
this flaw would lead to a denial of service (crash). To trigger this flaw
an attacker would need to have control of a kerberos realm that shares a
cross-realm key with the target, making exploitation of this flaw unlikely.
(CAN-2005-1175). 

Gaël Delalleau discovered an information disclosure issue in the way
some telnet clients handle messages from a server. An attacker could
construct a malicious telnet server that collects information from the
environment of any victim who connects to it using the Kerberos-aware
telnet client (CAN-2005-0488).

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses the Kerberos-aware rcp to copy files from a
malicious server (CAN-2004-0175). 

All users of krb5 should update to these erratum packages which contain
backported patches to correct these issues. Red Hat would like to thank
the MIT Kerberos Development Team for their responsible disclosure of these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-07-12" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0488.html">CVE-2005-0488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1175.html">CVE-2005-1175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1689.html">CVE-2005-1689</cve>
                <bugzilla href="http://bugzilla.redhat.com/159304" id="159304">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159753" id="159753">CAN-2005-1689 double-free in krb5_recvauth</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161471" id="161471">krb5 krb5_principal_compare NULL pointer crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161611" id="161611">CAN-2004-0175 malicious rsh server can cause rcp to write to arbitrary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162255" id="162255">CAN-2005-1175 krb5 buffer overflow in KDC</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562006" comment="krb5-libs is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562004" comment="krb5-devel is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562008" comment="krb5-server is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562002" comment="krb5 is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050562010" comment="krb5-workstation is earlier than 0:1.2.7-47" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050564" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:564: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:564-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-564.html" />
          <reference source="CVE" ref_id="CVE-2005-1751" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1751.html" />
          <reference source="CVE" ref_id="CVE-2005-1921" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1921.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was discovered in the PEAR XML-RPC Server package included in PHP.
If a PHP script is used which implements an XML-RPC Server using the PEAR
XML-RPC package, then it is possible for a remote attacker to construct an
XML-RPC request which can cause PHP to execute arbitrary PHP commands as
the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1921 to this issue.

When using the default SELinux "targeted" policy on Red Hat Enterprise
Linux 4, the impact of this issue is reduced since the scripts executed by
PHP are constrained within the httpd_sys_script_t security context.

A race condition in temporary file handling was discovered in the shtool
script installed by PHP.  If a third-party PHP module which uses shtool was
compiled as root, a local user may be able to modify arbitrary files.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-1751 to this issue.

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-07" />
        <updated date="2005-07-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1751.html">CVE-2005-1751</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1921.html">CVE-2005-1921</cve>
                <bugzilla href="http://bugzilla.redhat.com/158904" id="158904">Incorrect descriptions for php-ncurses and php-gd packages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159000" id="159000">CAN-2005-1751 shtool insecure temporary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162044" id="162044">CAN-2005-1921 PHP PEAR XML_RPC arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564014" comment="php-odbc is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564010" comment="php-mysql is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564002" comment="php is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564012" comment="php-pgsql is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564004" comment="php-devel is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564006" comment="php-imap is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564008" comment="php-ldap is earlier than 0:4.3.2-24.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564036" comment="php-gd is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564025" comment="php-odbc is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564023" comment="php-mysql is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564017" comment="php is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564030" comment="php-xmlrpc is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564032" comment="php-mbstring is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564024" comment="php-pgsql is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564018" comment="php-devel is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564034" comment="php-ncurses is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564026" comment="php-snmp is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564021" comment="php-imap is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564019" comment="php-pear is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564028" comment="php-domxml is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050564022" comment="php-ldap is earlier than 0:4.3.9-3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050567" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:567: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:567-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-567.html" />
          <reference source="CVE" ref_id="CVE-2004-0175" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0175.html" />
          <reference source="CVE" ref_id="CVE-2005-1174" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1174.html" />
          <reference source="CVE" ref_id="CVE-2005-1175" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1175.html" />
          <reference source="CVE" ref_id="CVE-2005-1689" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1689.html" />
    
    <description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A double-free flaw was found in the krb5_recvauth() routine which may be
triggered by a remote unauthenticated attacker.  Red Hat Enterprise Linux 4
contains checks within glibc that detect double-free flaws.  Therefore, on
Red Hat Enterprise Linux 4 successful exploitation of this issue can only
lead to a denial of service (KDC crash).  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-1689 to this issue.

Daniel Wachdorf discovered a single byte heap overflow in the
krb5_unparse_name() function, part of krb5-libs.  Sucessful exploitation of
this flaw would lead to a denial of service (crash).  To trigger this flaw
an attacker would need to have control of a kerberos realm that shares a
cross-realm key with the target, making exploitation of this flaw unlikely.
(CAN-2005-1175).

Daniel Wachdorf also discovered that in error conditions that may occur in
response to correctly-formatted client requests, the Kerberos 5 KDC may
attempt to free uninitialized memory.  This could allow a remote attacker
to cause a denial of service (KDC crash) (CAN-2005-1174).

Gaël Delalleau discovered an information disclosure issue in the way
some telnet clients handle messages from a server. An attacker could
construct a malicious telnet server that collects information from the
environment of any victim who connects to it using the Kerberos-aware
telnet client (CAN-2005-0488).

The rcp protocol allows a server to instruct a client to write to arbitrary
files outside of the current directory. This could potentially cause a
security issue if a user uses the Kerberos-aware rcp to copy files from a
malicious server (CAN-2004-0175).

All users of krb5 should update to these erratum packages, which contain
backported patches to correct these issues.  Red Hat would like to thank
the MIT Kerberos Development Team for their responsible disclosure of these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-07-12" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0175.html">CVE-2004-0175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1174.html">CVE-2005-1174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1175.html">CVE-2005-1175</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1689.html">CVE-2005-1689</cve>
                <bugzilla href="http://bugzilla.redhat.com/157103" id="157103">CAN-2005-1174 krb5 buffer overflow, heap corruption in KDC (CAN-2005-1175)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159304" id="159304">CAN-2005-0488 telnet Information Disclosure Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159756" id="159756">CAN-2005-1689 double-free in krb5_recvauth</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161471" id="161471">krb5 krb5_principal_compare NULL pointer crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161611" id="161611">CAN-2004-0175 malicious rsh server can cause rcp to write to arbitrary files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567006" comment="krb5-libs is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567004" comment="krb5-devel is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567008" comment="krb5-server is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567002" comment="krb5 is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050567010" comment="krb5-workstation is earlier than 0:1.3.4-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050569" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:569: zlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-569.html" />
          <reference source="CVE" ref_id="CVE-2005-2096" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2096.html" />
    
    <description>Zlib is a general-purpose lossless data compression library which is used
by many different programs.

Tavis Ormandy discovered a buffer overflow affecting Zlib version 1.2 and
above.  An attacker could create a carefully crafted compressed stream that
would cause an application to crash if the stream is opened by a user.  As
an example, an attacker could create a malicious PNG image file which would
cause a web browser or mail viewer to crash if the image is viewed.  The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2096 to this issue.

Please note that the versions of Zlib as shipped with Red Hat Enterprise
Linux 2.1 and 3 are not vulnerable to this issue.

All users should update to these erratum packages which contain a patch
from Mark Adler which corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-06" />
        <updated date="2005-07-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2096.html">CVE-2005-2096</cve>
                <bugzilla href="http://bugzilla.redhat.com/162391" id="162391">CAN-2005-2096 zlib buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050569002" comment="zlib is earlier than 0:1.2.1.2-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569003" comment="zlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050569004" comment="zlib-devel is earlier than 0:1.2.1.2-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569005" comment="zlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050571" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:571: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:571-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-571.html" />
          <reference source="CVE" ref_id="CVE-2004-2154" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2154.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer for
UNIX(R) operating systems.

When processing a request, the CUPS scheduler would use case-sensitive
matching on the queue name to decide which authorization policy should be
used.  However, queue names are not case-sensitive.  An unauthorized user
could print to a password-protected queue without needing a password.  The
Common Vulnerabilities and Exposures project has assigned the name
CAN-2005-2154 to this issue.

Please note that the version of CUPS included in Red Hat Enterprise Linux 4
is not vulnerable to this issue.

All users of CUPS should upgrade to these erratum packages which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-14" />
        <updated date="2005-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2154.html">CVE-2004-2154</cve>
                <bugzilla href="http://bugzilla.redhat.com/162405" id="162405">CAN-2004-2154 &lt;Location ...> directive is case-sensitive in cupsd.conf but should not</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571004" comment="cups-devel is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571006" comment="cups-libs is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050571002" comment="cups is earlier than 1:1.1.17-13.3.29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050582" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:582: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:582-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-582.html" />
          <reference source="CVE" ref_id="CVE-2005-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1268.html" />
          <reference source="CVE" ref_id="CVE-2005-2088" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2088.html" />
    
    <description>The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

Watchfire reported a flaw that occured when using the Apache server as an
HTTP proxy.  A remote attacker could send an HTTP request with both a
"Transfer-Encoding: chunked" header and a "Content-Length" header.  This
caused Apache to incorrectly handle and forward the body of the request in
a way that the receiving server processes it as a separate HTTP request.
This could allow the bypass of Web application firewall protection or lead
to cross-site scripting (XSS) attacks.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) assigned the name CAN-2005-2088 to this
issue.

Marc Stern reported an off-by-one overflow in the mod_ssl CRL verification
callback.  In order to exploit this issue the Apache server would need to
be configured to use a malicious certificate revocation list (CRL).   The
Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the
name CAN-2005-1268 to this issue.

Users of Apache httpd should update to these errata packages that contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-25" />
        <updated date="2005-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1268.html">CVE-2005-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2088.html">CVE-2005-2088</cve>
                <bugzilla href="http://bugzilla.redhat.com/161893" id="161893">Bug 145666 is missing a ',' after REDIRECT_REMOTE_USER</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162244" id="162244">CAN-2005-2088 httpd proxy request smuggling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163013" id="163013">CAN-2005-1268 mod_ssl off-by-one</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582004" comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582006" comment="mod_ssl is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582002" comment="httpd is earlier than 0:2.0.46-46.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582011" comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582012" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582014" comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582015" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582010" comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582013" comment="mod_ssl is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050582009" comment="httpd is earlier than 0:2.0.52-12.1.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050584" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:584: zlib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:584-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-584.html" />
          <reference source="CVE" ref_id="CVE-2005-1849" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1849.html" />
    
    <description>Zlib is a general-purpose lossless data compression library that is used
by many different programs.

A previous zlib update, RHSA-2005:569 (CAN-2005-2096) fixed a flaw in zlib
that could allow a carefully crafted compressed stream to crash an
application. While the original patch corrected the reported overflow,
Markus Oberhumer discovered additional ways a stream could trigger an
overflow.  An attacker could create a carefully crafted compressed stream
that would cause an application to crash if the stream is opened by a user.
 As an example, an attacker could create a malicious PNG image file that
would cause a Web browser or mail viewer to crash if the image is viewed.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned
the name CAN-2005-1849 to this issue.

Note that the versions of zlib shipped with Red Hat Enterprise
Linux 2.1 and 3 are not vulnerable to this issue.

All users should update to these errata packages that contain a patch
from Mark Adler that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1849.html">CVE-2005-1849</cve>
                <bugzilla href="http://bugzilla.redhat.com/163037" id="163037">CAN-2005-1849 zlib buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050584002" comment="zlib is earlier than 0:1.2.1.2-1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569003" comment="zlib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050584004" comment="zlib-devel is earlier than 0:1.2.1.2-1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050569005" comment="zlib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050586" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:586: firefox security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-586.html" />
          <reference source="CVE" ref_id="CVE-2005-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1937.html" />
          <reference source="CVE" ref_id="CVE-2005-2114" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2114.html" />
          <reference source="CVE" ref_id="CVE-2005-2260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2260.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2262" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2262.html" />
          <reference source="CVE" ref_id="CVE-2005-2263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2263.html" />
          <reference source="CVE" ref_id="CVE-2005-2264" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2264.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2267.html" />
          <reference source="CVE" ref_id="CVE-2005-2268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2268.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox handled synthetic events. It is possible
that Web content could generate events such as keystrokes or mouse clicks
that could be used to steal data or execute malicious JavaScript code. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-2260 to this issue.


A bug was found in the way Firefox executed Javascript in XBL controls. It
is possible for a malicious webpage to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261)

A bug was found in the way Firefox set an image as the desktop wallpaper.
If a user chooses the "Set As Wallpaper..." context menu item on a
specially crafted image, it is possible for an attacker to execute
arbitrary code on a victim's machine. (CAN-2005-2262)

A bug was found in the way Firefox installed its extensions. If a user can
be tricked into visiting a malicious webpage, it may be possible to obtain
sensitive information such as cookies or passwords. (CAN-2005-2263)

A bug was found in the way Firefox handled the _search target. It is
possible for a malicious website to inject JavaScript into an already open
webpage. (CAN-2005-2264)

A bug was found in the way Firefox handled certain Javascript functions. It
is possible for a malicious web page to crash the browser by executing
malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Firefox handled multiple frame domains. It is
possible for a frame as part of a malicious web site to inject content into
a frame that belongs to another domain. This issue was previously fixed as
CAN-2004-0718 but was accidentally disabled. (CAN-2005-1937)

A bug was found in the way Firefox handled child frames. It is possible for
a malicious framed page to steal sensitive information from its parent
page. (CAN-2005-2266)

A bug was found in the way Firefox opened URLs from media players. If a
media player opens a URL that is JavaScript, JavaScript is executed
with access to the currently open webpage. (CAN-2005-2267)

A design flaw was found in the way Firefox displayed alerts and prompts.
Alerts and prompts were given the generic title [JavaScript Application]
which prevented a user from knowing which site created them. (CAN-2005-2268)

A bug was found in the way Firefox handled DOM node names. It is possible
for a malicious site to overwrite a DOM node name, allowing certain
privileged chrome actions to execute the malicious JavaScript. (CAN-2005-2269)

A bug was found in the way Firefox cloned base objects. It is possible for
Web content to navigate up the prototype chain to gain access to privileged
chrome objects. (CAN-2005-2270)

Users of Firefox are advised to upgrade to this updated package that
contains Firefox version 1.0.6 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1937.html">CVE-2005-1937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2114.html">CVE-2005-2114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2260.html">CVE-2005-2260</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2262.html">CVE-2005-2262</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2263.html">CVE-2005-2263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2264.html">CVE-2005-2264</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2267.html">CVE-2005-2267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2268.html">CVE-2005-2268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163069" id="163069">CAN-2005-1937 multiple firefox security issues (CAN-2005-2260 CAN-2005-2261 CAN-2005-2262 CAN-2005-2263 CAN-2005-2264 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050586002" comment="firefox is earlier than 0:1.0.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050587" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:587: mozilla security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:587-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-587.html" />
          <reference source="CVE" ref_id="CVE-2005-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1937.html" />
          <reference source="CVE" ref_id="CVE-2005-2114" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2114.html" />
          <reference source="CVE" ref_id="CVE-2005-2260" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2260.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2263" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2263.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2267" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2267.html" />
          <reference source="CVE" ref_id="CVE-2005-2268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2268.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla handled synthetic events. It is possible
that Web content could generate events such as keystrokes or mouse clicks
that could be used to steal data or execute malicious Javascript code. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-2260 to this issue. 

A bug was found in the way Mozilla executed Javascript in XBL controls. It
is possible for a malicious webpage to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261) 

A bug was found in the way Mozilla installed its extensions. If a user can
be tricked into visiting a malicious webpage, it may be possible to obtain
sensitive information such as cookies or passwords. (CAN-2005-2263)

A bug was found in the way Mozilla handled certain Javascript functions. It
is possible for a malicious webpage to crash the browser by executing
malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Mozilla handled multiple frame domains. It is
possible for a frame as part of a malicious website to inject content into
a frame that belongs to another domain. This issue was previously fixed as
CAN-2004-0718 but was accidentally disabled. (CAN-2005-1937) 

A bug was found in the way Mozilla handled child frames. It is possible for
a malicious framed page to steal sensitive information from its parent
page. (CAN-2005-2266)

A bug was found in the way Mozilla opened URLs from media players. If a
media player opens a URL which is Javascript, the Javascript executes
with access to the currently open webpage. (CAN-2005-2267)

A design flaw was found in the way Mozilla displayed alerts and prompts.
Alerts and prompts were given the generic title [JavaScript Application]
which prevented a user from knowing which site created them. (CAN-2005-2268)

A bug was found in the way Mozilla handled DOM node names. It is possible
for a malicious site to overwrite a DOM node name, allowing certain
privileged chrome actions to execute the malicious Javascript. (CAN-2005-2269)

A bug was found in the way Mozilla cloned base objects. It is possible for
Web content to traverse the prototype chain to gain access to privileged
chrome objects. (CAN-2005-2270)

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.7.10 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-22" />
        <updated date="2005-07-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1937.html">CVE-2005-1937</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2114.html">CVE-2005-2114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2260.html">CVE-2005-2260</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2263.html">CVE-2005-2263</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2267.html">CVE-2005-2267</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2268.html">CVE-2005-2268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163065" id="163065">CAN-2005-1937 multiple mozilla issues (CAN-2005-2260 CAN-2005-2261 CAN-2005-2263 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587018" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587014" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587016" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587010" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587002" comment="mozilla is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587020" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587006" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587004" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587012" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587008" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587031" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587029" comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587030" comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587027" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587023" comment="mozilla is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587032" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587025" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587024" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587028" comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587026" comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587033" comment="devhelp is earlier than 0:0.9.2-2.4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050587035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050595" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:595: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:595-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-595.html" />
          <reference source="CVE" ref_id="CVE-2005-2095" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2095.html" />
          <reference source="CVE" ref_id="CVE-2005-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1769.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4.

A bug was found in the way SquirrelMail handled the $_POST variable. If a
user is tricked into visiting a malicious URL, the user's SquirrelMail
preferences could be read or modified. The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2095 to this issue.

Several cross-site scripting bugs were discovered in SquirrelMail. An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL, or by sending them a carefully constructed HTML email message. The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-1769 to this issue. 

All users of SquirrelMail should upgrade to this updated package, which
contains backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-03" />
        <updated date="2005-08-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2095.html">CVE-2005-2095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1769.html">CVE-2005-1769</cve>
                <bugzilla href="http://bugzilla.redhat.com/160241" id="160241">CAN-2005-1769 Multiple XSS issues in squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162275" id="162275">CAN-2005-2095 squirrelmail cross site posting issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050595002" comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050595005" comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050099003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050598" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:598: sysreport security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:598-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-598.html" />
          <reference source="CVE" ref_id="CVE-2005-2104" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2104.html" />
    
    <description>Sysreport is a utility that gathers information about a system's hardware
and configuration. The information can then be used for diagnostic purposes
and debugging.

Bill Stearns discovered a bug in the way sysreport creates temporary files.
It is possible that a local attacker could obtain sensitive information
about the system when sysreport is run. The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2104 to this issue.

Users of sysreport should update to this erratum package, which contains a
patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2104.html">CVE-2005-2104</cve>
                <bugzilla href="http://bugzilla.redhat.com/162978" id="162978">CAN-2005-2104 sysreport insecure temporary directory usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050598002" comment="sysreport is earlier than 0:1.3.7.2-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050598005" comment="sysreport is earlier than 0:1.3.15-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050502003" comment="sysreport is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050601" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:601: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:601-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-601.html" />
          <reference source="CVE" ref_id="CVE-2005-0989" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0989.html" />
          <reference source="CVE" ref_id="CVE-2005-1159" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1159.html" />
          <reference source="CVE" ref_id="CVE-2005-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1160.html" />
          <reference source="CVE" ref_id="CVE-2005-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1532.html" />
          <reference source="CVE" ref_id="CVE-2005-2261" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2261.html" />
          <reference source="CVE" ref_id="CVE-2005-2265" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2265.html" />
          <reference source="CVE" ref_id="CVE-2005-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2266.html" />
          <reference source="CVE" ref_id="CVE-2005-2269" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2269.html" />
          <reference source="CVE" ref_id="CVE-2005-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2270.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird handled anonymous functions during
regular expression string replacement. It is possible for a malicious HTML
mail to capture a random block of client memory. The Common
Vulnerabilities and Exposures project has assigned this bug the name
CAN-2005-0989.

A bug was found in the way Thunderbird validated several XPInstall related
JavaScript objects. A malicious HTML mail could pass other objects to the
XPInstall objects, resulting in the JavaScript interpreter jumping to
arbitrary locations in memory. (CAN-2005-1159)

A bug was found in the way the Thunderbird privileged UI code handled DOM
nodes from the content window. An HTML message could install malicious
JavaScript code or steal data when a user performs commonplace actions such
as clicking a link or opening the context menu. (CAN-2005-1160)

A bug was found in the way Thunderbird executed JavaScript code. JavaScript
executed from HTML mail should run with a restricted access level,
preventing dangerous actions. It is possible that a malicious HTML mail
could execute JavaScript code with elevated privileges, allowing access to
protected data and functions. (CAN-2005-1532)

A bug was found in the way Thunderbird executed Javascript in XBL controls.
It is possible for a malicious HTML mail to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CAN-2005-2261)

A bug was found in the way Thunderbird handled certain Javascript
functions. It is possible for a malicious HTML mail to crash the client by
executing malformed Javascript code. (CAN-2005-2265)

A bug was found in the way Thunderbird handled child frames. It is possible
for a malicious framed HTML mail to steal sensitive information from its
parent frame. (CAN-2005-2266) 

A bug was found in the way Thunderbird handled DOM node names. It is
possible for a malicious HTML mail to overwrite a DOM node name, allowing
certain privileged chrome actions to execute the malicious JavaScript.
(CAN-2005-2269)

A bug was found in the way Thunderbird cloned base objects. It is possible
for HTML content to navigate up the prototype chain to gain access to
privileged chrome objects. (CAN-2005-2270) 

Users of Thunderbird are advised to upgrade to this updated package that
contains Thunderbird version 1.0.6 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0989.html">CVE-2005-0989</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1159.html">CVE-2005-1159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1160.html">CVE-2005-1160</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1532.html">CVE-2005-1532</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2261.html">CVE-2005-2261</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2265.html">CVE-2005-2265</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2266.html">CVE-2005-2266</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2269.html">CVE-2005-2269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2270.html">CVE-2005-2270</cve>
                <bugzilla href="http://bugzilla.redhat.com/163285" id="163285">CAN-2005-0989 multiple thunderbird issues (CAN-2005-1159 CAN-2005-1160 CAN-2005-1532 CAN-2005-2261 CAN-2005-2265 CAN-2005-2266 CAN-2005-2269 CAN-2005-2270)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050601002" comment="thunderbird is earlier than 0:1.0.6-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050608" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:608: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:608-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-608.html" />
          <reference source="CVE" ref_id="CVE-2005-2700" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2700.html" />
          <reference source="CVE" ref_id="CVE-2005-2728" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2728.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was discovered in mod_ssl's handling of the "SSLVerifyClient"
directive.  This flaw occurs if a virtual host is configured
using "SSLVerifyClient optional" and a directive "SSLVerifyClient
required" is set for a specific location.  For servers configured in this
fashion, an attacker may be able to access resources that should otherwise
be protected, by not supplying a client certificate when connecting.  The
Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2700 to this issue.

A flaw was discovered in Apache httpd where the byterange filter would
buffer certain responses into memory.  If a server has a dynamic
resource such as a CGI script or PHP script that generates a large amount
of data, an attacker could send carefully crafted requests in order to
consume resources, potentially leading to a Denial of Service.  (CAN-2005-2728)

Users of Apache httpd should update to these errata packages that contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-06" />
        <updated date="2005-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2700.html">CVE-2005-2700</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2728.html">CVE-2005-2728</cve>
                <bugzilla href="http://bugzilla.redhat.com/167102" id="167102">CAN-2005-2728 byterange memory DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167194" id="167194">CAN-2005-2700 SSLVerifyClient flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608004" comment="httpd-devel is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608006" comment="mod_ssl is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608002" comment="httpd is earlier than 0:2.0.46-46.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608011" comment="httpd-manual is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582012" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608014" comment="httpd-suexec is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582015" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608010" comment="httpd-devel is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608013" comment="mod_ssl is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050608009" comment="httpd is earlier than 0:2.0.52-12.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050582003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050612" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:612: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:612-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-612.html" />
          <reference source="CVE" ref_id="CVE-2005-1920" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1920.html" />
    
    <description>kdelibs contains libraries for the K Desktop Environment.

A flaw was discovered affecting Kate, the KDE advanced text editor, and
Kwrite.  Depending on system settings, it may be possible for a local user
to read the backup files created by Kate or Kwrite.  The Common
Vulnerabilities and Exposures project assigned the name CAN-2005-1920 to
this issue.

Please note this issue does not affect Red Hat Enterprise Linux 3 or 2.1.

Users of Kate or Kwrite should update to these errata packages which
contains a backported patch from the KDE security team correcting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-27" />
        <updated date="2005-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1920.html">CVE-2005-1920</cve>
                <bugzilla href="http://bugzilla.redhat.com/163130" id="163130">CAN-2005-1920 Kate backup file permissions leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050612002" comment="kdelibs is earlier than 6:3.3.1-3.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050612004" comment="kdelibs-devel is earlier than 6:3.3.1-3.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050627" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:627: gaim security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:627-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-627.html" />
          <reference source="CVE" ref_id="CVE-2005-2102" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2102.html" />
          <reference source="CVE" ref_id="CVE-2005-2103" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2103.html" />
          <reference source="CVE" ref_id="CVE-2005-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2370.html" />
    
    <description>Gaim is an Internet Messaging client.

A heap based buffer overflow issue was discovered in the way Gaim processes
away messages. A remote attacker could send a specially crafted away
message to a Gaim user logged into AIM or ICQ that could result in
arbitrary code execution. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2103 to this issue.

Daniel Atallah discovered a denial of service issue in Gaim. A remote
attacker could attempt to upload a file with a specially crafted name to a
user logged into AIM or ICQ, causing Gaim to crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2102 to this issue.

A denial of service bug was found in Gaim's Gadu Gadu protocol handler. A
remote attacker could send a specially crafted message to a Gaim user
logged into Gadu Gadu, causing Gaim to crash.  Please note that this issue
only affects PPC and IBM S/390 systems running Gaim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-2370 to this issue.

Users of gaim are advised to upgrade to this updated package, which
contains backported patches and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2102.html">CVE-2005-2102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2103.html">CVE-2005-2103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2370.html">CVE-2005-2370</cve>
                <bugzilla href="http://bugzilla.redhat.com/165392" id="165392">CAN-2005-2370 gadu gadu memory alignment issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165400" id="165400">CAN-2005-2102 gaim AIM invalid filename DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165402" id="165402">CAN-2005-2103 Gaim malformed away message remote code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050627002" comment="gaim is earlier than 1:1.3.1-0.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050627005" comment="gaim is earlier than 1:1.3.1-0.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050215003" comment="gaim is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050639" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:639: kdenetwork security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:639-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-639.html" />
          <reference source="CVE" ref_id="CVE-2005-1852" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1852.html" />
          <reference source="CVE" ref_id="CVE-2005-2369" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2369.html" />
          <reference source="CVE" ref_id="CVE-2005-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2370.html" />
          <reference source="CVE" ref_id="CVE-2005-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2448.html" />
    
    <description>The kdenetwork package contains networking applications for the K Desktop
Environment.  Kopete is a KDE instant messenger which supports a number of
protocols including ICQ, MSN, Yahoo, Jabber, and Gadu-Gadu.

Multiple integer overflow flaws were found in the way Kopete processes
Gadu-Gadu messages. A remote attacker could send a specially crafted
Gadu-Gadu message which would cause Kopete to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-1852 to this issue.

In order to be affected by this issue, a user would need to have registered
with Gadu-Gadu and be signed in to the Gadu-Gadu server in order to receive
a malicious message.  In addition, Red Hat believes that the Exec-shield
technology (enabled by default in Red Hat Enterprise Linux 4) would block
attempts to remotely exploit this vulnerability.

Note that this issue does not affect Red Hat Enterprise Linux 2.1 or 3.

Users of Kopete should update to these packages which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-21" />
        <updated date="2005-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1852.html">CVE-2005-1852</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2369.html">CVE-2005-2369</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2370.html">CVE-2005-2370</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2448.html">CVE-2005-2448</cve>
                <bugzilla href="http://bugzilla.redhat.com/163811" id="163811">CAN-2005-1852 Kopete gadu-gadu flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639002" comment="kdenetwork is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175003" comment="kdenetwork is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639006" comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050639007" comment="kdenetwork-nowlistening is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050639004" comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050175005" comment="kdenetwork-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050640" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:640: fetchmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:640-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-640.html" />
          <reference source="CVE" ref_id="CVE-2005-2335" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2335.html" />
    
    <description>Fetchmail is a remote mail retrieval and forwarding utility.

A buffer overflow was discovered in fetchmail's POP3 client.  A malicious
server could cause send a carefully crafted message UID and cause fetchmail
to crash or potentially execute arbitrary code as the user running
fetchmail.  The Common Vulnerabilities and Exposures project assigned the
name CAN-2005-2335 to this issue.

Users of fetchmail should update to this erratum package which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-07-25" />
        <updated date="2005-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2335.html">CVE-2005-2335</cve>
                <bugzilla href="http://bugzilla.redhat.com/163816" id="163816">CAN-2005-2335 fetchmail overflow from malicious pop3 server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640002" comment="fetchmail is earlier than 0:6.2.0-3.el3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640005" comment="fetchmail is earlier than 0:6.2.5-6.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050640003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050659" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:659: binutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:659-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-659.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>Binutils is a collection of utilities used for the creation of executable
code. A number of bugs were found in various binutils tools.  

Several integer overflow bugs were found in binutils. If a user is tricked
into processing a specially crafted executable with utilities such as
readelf, size, strings, objdump, or nm, it may allow the execution of
arbitrary code as the user running the utility. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1704
to this issue.

Additionally, the following bugs have been fixed:

-- correct alignment of .tbss section if the requested alignment
   of .tbss is bigger than requested alignment of .tdata section
-- by default issue an error if IA-64 hint@pause instruction is
   put into the B slot, add assembler command line switch to
   override this behaviour

All users of binutils should upgrade to this updated package, which
contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/157983" id="157983">gcc produces inadequate alignment for __thread vars</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164364" id="164364">CAN-2005-1704 Integer overflow in the Binary File Descriptor (BFD) library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659002" comment="binutils is earlier than 0:2.14.90.0.4-39" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659003" comment="binutils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050663" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:663: Updated kernel packages available for Red Hat Enterprise Linux 3 Update 6 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:663-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-663.html" />
          <reference source="CVE" ref_id="CVE-2004-0181" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0181.html" />
          <reference source="CVE" ref_id="CVE-2004-1056" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1056.html" />
          <reference source="CVE" ref_id="CVE-2005-0124" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0124.html" />
          <reference source="CVE" ref_id="CVE-2005-0136" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0136.html" />
          <reference source="CVE" ref_id="CVE-2005-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0179.html" />
          <reference source="CVE" ref_id="CVE-2005-0210" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0210.html" />
          <reference source="CVE" ref_id="CVE-2005-0400" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0400.html" />
          <reference source="CVE" ref_id="CVE-2005-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0504.html" />
          <reference source="CVE" ref_id="CVE-2005-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0756.html" />
          <reference source="CVE" ref_id="CVE-2005-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0815.html" />
          <reference source="CVE" ref_id="CVE-2005-1761" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1761.html" />
          <reference source="CVE" ref_id="CVE-2005-1762" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1762.html" />
          <reference source="CVE" ref_id="CVE-2005-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1767.html" />
          <reference source="CVE" ref_id="CVE-2005-1768" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1768.html" />
          <reference source="CVE" ref_id="CVE-2005-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2456.html" />
          <reference source="CVE" ref_id="CVE-2005-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2490.html" />
          <reference source="CVE" ref_id="CVE-2005-2553" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2553.html" />
          <reference source="CVE" ref_id="CVE-2005-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2555.html" />
          <reference source="CVE" ref_id="CVE-2005-3273" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3273.html" />
          <reference source="CVE" ref_id="CVE-2005-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3274.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the sixth regular kernel update to Red Hat Enterprise Linux 3.

New features introduced by this update include:

  - diskdump support on HP Smart Array devices
  - netconsole/netdump support over bonded interfaces
  - new chipset and device support via PCI table updates
  - support for new "oom-kill" and "kscand_work_percent" sysctls
  - support for dual core processors and ACPI Power Management timers on
      AMD64 and Intel EM64T systems

There were many bug fixes in various parts of the kernel.  The ongoing
effort to resolve these problems has resulted in a marked improvement in
the reliability and scalability of Red Hat Enterprise Linux 3.

There were numerous driver updates and security fixes (elaborated below).
Other key areas affected by fixes in this update include kswapd, inode
handling, the SATA subsystem, diskdump handling, ptrace() syscall support,
and signal handling.

The following device drivers have been upgraded to new versions:

  3w-9xxx ---- 2.24.03.008RH
  cciss ------ 2.4.58.RH1
  e100 ------- 3.4.8-k2
  e1000 ------ 6.0.54-k2
  emulex ----- 7.3.2
  fusion ----- 2.06.16i.01
  iscsi ------ 3.6.2.1
  ipmi ------- 35.4
  lpfcdfc ---- 1.2.1
  qlogic ----- 7.05.00-RH1
  tg3 -------- 3.27RH

The following security bugs were fixed in this update:

  - a flaw in syscall argument checking on Itanium systems that allowed
    a local user to cause a denial of service (crash)  (CAN-2005-0136)

  - a flaw in stack expansion that allowed a local user of mlockall()
    to cause a denial of service (memory exhaustion)  (CAN-2005-0179)

  - a small memory leak in network packet defragmenting that allowed a
    remote user to cause a denial of service (memory exhaustion) on
    systems using netfilter  (CAN-2005-0210)

  - flaws in ptrace() syscall handling on AMD64 and Intel EM64T systems
    that allowed a local user to cause a denial of service (crash)
    (CAN-2005-0756, CAN-2005-1762, CAN-2005-2553)

  - flaws in ISO-9660 file system handling that allowed the mounting of
    an invalid image on a CD-ROM to cause a denial of service (crash)
    or potentially execute arbitrary code  (CAN-2005-0815)

  - a flaw in ptrace() syscall handling on Itanium systems that allowed
    a local user to cause a denial of service (crash)  (CAN-2005-1761)

  - a flaw in the alternate stack switching on AMD64 and Intel EM64T
    systems that allowed a local user to cause a denial of service
    (crash)  (CAN-2005-1767)

  - race conditions in the ia32-compat support for exec() syscalls on
    AMD64, Intel EM64T, and Itanium systems that could allow a local
    user to cause a denial of service (crash)  (CAN-2005-1768)

  - flaws in IPSEC network handling that allowed a local user to cause
    a denial of service or potentially gain privileges  (CAN-2005-2456,
    CAN-2005-2555)

  - a flaw in sendmsg() syscall handling on 64-bit systems that allowed
    a local user to cause a denial of service or potentially gain
    privileges  (CAN-2005-2490)

  - flaws in unsupported modules that allowed denial-of-service attacks
    (crashes) or local privilege escalations on systems using the drm,
    coda, or moxa modules  (CAN-2004-1056, CAN-2005-0124, CAN-2005-0504)

  - potential leaks of kernel data from jfs and ext2 file system handling
    (CAN-2004-0181, CAN-2005-0400)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0181.html">CVE-2004-0181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1056.html">CVE-2004-1056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0124.html">CVE-2005-0124</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0136.html">CVE-2005-0136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0179.html">CVE-2005-0179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0210.html">CVE-2005-0210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0400.html">CVE-2005-0400</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0504.html">CVE-2005-0504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0756.html">CVE-2005-0756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0815.html">CVE-2005-0815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1761.html">CVE-2005-1761</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1762.html">CVE-2005-1762</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1767.html">CVE-2005-1767</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1768.html">CVE-2005-1768</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2456.html">CVE-2005-2456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2490.html">CVE-2005-2490</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2553.html">CVE-2005-2553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2555.html">CVE-2005-2555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3273.html">CVE-2005-3273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3274.html">CVE-2005-3274</cve>
                <bugzilla href="http://bugzilla.redhat.com/79086" id="79086">Request for enhancement for callback function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/98542" id="98542">iostat -x shows infeasible avgqu-sz results and max util</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/99502" id="99502">LTC3549 - ps wchan broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116037" id="116037">Existence of race condition in Linux SD driver that leads to a deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116317" id="116317">symbolic links have invalid permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/116900" id="116900">RHEL3_U4 Data corruption in spite of using O_SYNC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/119451" id="119451">System can hang while running multiple instances of fdisk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/121041" id="121041">CVE-2004-0181 jfs infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/122982" id="122982">microcode_ctl errors with modprobe: Can't locate module char-major-10-184</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/123331" id="123331">LUN  i not getting registered</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128428" id="128428">Opteron gettimeofday granularity problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128788" id="128788">RHEL3 U6: Diskdump support for Compaq Smart Array Controllers (cciss)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/128907" id="128907">iostat -x 1 5 give bogus statistics...</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/129853" id="129853">RHEL3 U4:  need netdump to work with the bonding driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131029" id="131029">gart errors when using 2.4.21-15.0.3.EL.smp or -9.0.1 on AMD64 quad system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131136" id="131136">[Patch] Simultaneous calls to open() on a usb device hangs the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131886" id="131886">__put_task_struct unresolved when loading externally compiled module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/132754" id="132754">char-major-10-184 microcode error with kernel 2.4.21-15.ELhugemem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/134579" id="134579">bogus data in /proc/partitions for IDE whole-disk device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137788" id="137788">Extraneous data in option name for scsi_mod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138192" id="138192">gart errors when using 2.4.21-20.EL on HP DL585</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/138534" id="138534">CVE-2004-1056 insufficient locking checks in DRM code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139033" id="139033">RHEL3 U5: netdump does not work over bonded interfaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139113" id="139113">System hangs for 15-45 seconds on RHEL3 / kernel 2.4.21-20.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/140849" id="140849">"fdisk -l" broken when over 26 EMC Powerpath disks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142263" id="142263">Only 16 EMC powerpath LUNs usable with LVM1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142532" id="142532">error unmounting /var filesystem while shutdown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142586" id="142586">Potential kernel DOS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142856" id="142856">'ghosted' autofs shares disappear</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/142960" id="142960">Unable to umount /var during shutdown process when connected with ssh</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/143823" id="143823">[PATCH] Stale POSIX flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144524" id="144524">CVE-2005-0179 RLIMIT_MEMLOCK bypass and (2.6) unprivileged user DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144781" id="144781">Kernel panic in shutdown path when iSCSI LUNs are mounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145476" id="145476">netdump client/server problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145551" id="145551">Use of bonding driver in mode 5 can cause multicast packet loss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145950" id="145950">high loads / high iowait / up 100% cpu time for kscand on oracle box</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146080" id="146080">CVE-2005-0124 Coverity: coda fs flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146105" id="146105">CVE-2005-0504 moxa CAP_SYS_RAWIO missing (-unsupported)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/146460" id="146460">Need openIPMI driver to work with IBM's x336 BMC [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147823" id="147823">FEAT: RHEL3 U6: Enable dual-core processors from Intel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148862" id="148862">CVE-2005-0136 ptrace corner cases on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149011" id="149011">Oracle 8 import of Oracle 9 database can lock system.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149405" id="149405">LTC13257-LTPstress sigaction01 Testcase Ends up Segmentation Fault [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149636" id="149636">Kernel panic (EIP is at find_inode)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149691" id="149691">No data avaliable for eth card</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149965" id="149965">panic at ia64_leave_kernel  [kernel] 0x1 (2.4.21-27.EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150019" id="150019">Don't oom kill TASK_UNINTERRUPTIBLE processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150130" id="150130">e1000 has memory leak when run continuously getting new dhcp leases.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150209" id="150209">Over time, autofs leaks kernel memory in the size-256 slab</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151054" id="151054">kernel panic when bringing up and down multiple interfaces simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151488" id="151488">sk98lin driver drops udp packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151920" id="151920">8GB SMP servers appear to hang in VM subsystem under stress</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152400" id="152400">CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152406" id="152406">CVE-2005-0815 isofs range checking flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153775" id="153775">[RHEL3-U6][Diskdump] Backtrace of OS_INIT doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154245" id="154245">RHEL3 U4 - kswapd/rpciod deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154678" id="154678">[Texas Instruments] nfs bindresvport: Address already in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154797" id="154797">[RHEL3 U6] diskdump fails with block_order=8</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154925" id="154925">[RHEL3 U6] Diskdump fails if module parameter 'block_order' has too big value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155244" id="155244">Kernel Panics on kernel 2.4.21-27</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155259" id="155259">[LSI Logic] Feature RHEL: Add mpt fusion SAS support, and new PCI IDs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155289" id="155289">[RHEL 3 U6]inode_lock deadlock/race?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155365" id="155365">CVE-2005-3273 ROSE ndigis verification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155473" id="155473">ext3 data corruption under Samba share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155978" id="155978">CVE-2005-1762 x86_64 sysret exception leads to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156142" id="156142">kernel may oops if more  than 4k worth of string data returned in /proc/devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156364" id="156364">[RHEL3] IPv6 Neighbor Cache : RHEL 3.0 does not update the IsRouter flag in the cache entry and improperly remove router from the Default Router List.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156608" id="156608">[RHEL3 U4] The system clock gains much time when netconle is activated.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156644" id="156644">CRM 479318 Unexpected IO-APIC on Opteron system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156831" id="156831">sd _mod doesn't handle removable drives (USB floppy) well</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156923" id="156923">PPC64 not setting backchain in signal frames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156985" id="156985">FEAT: RHEL3 U6: cciss driver updates (STOPSHIP)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156989" id="156989">FEAT: RH EL 3 U6: diskdump driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156991" id="156991">RHEL3 U6: Add 'ht' flag in EM64T /proc/cpuinfo [PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156993" id="156993">FEAT: RHEL3 U6: Add ICH4L support to kernel (MEDIUM)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156994" id="156994">529692 - /proc/stat documentation is out of date.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156998" id="156998">RHEL 3 U6: Use of Performance Monitoring Counters based on Model number (x86-64)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157075" id="157075">When an AX100i SP reboot occurs, the Cisco iSCSI driver doesnt log back into array.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157434" id="157434">FEAT RHEL3 U6:  Need e1000 driver Update to v.6.0.54 or higher (MUSTFIX)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157439" id="157439">LTC14642-NetDump is too slow to dump...[PATCH]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157446" id="157446">[RFE] [RHEL3 U6]Update 3w-9xxx driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157571" id="157571">[CRM 511714] bonding and arp ping failure detection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157669" id="157669">attempt to access beyond end of device: ext2 symlink/EA problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157846" id="157846">Potential kernel panic with stale POSIX locks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157849" id="157849">CVE-2005-3274 IPVS panic at ip_vs_conn_flush() when unloading ip_vs module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158358" id="158358">Updated Qlogic driver is requested in RHEL 3 U6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158456" id="158456">Update Emulex driver in RHEL 3 U6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158457" id="158457">Long tape commands (e.g. erase)  timeout on dpt_i2o.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158459" id="158459">RHEL 3 configures non-existent SCSI target devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158581" id="158581">FEAT RHEL3U6:  new devices supported by tg3 (STOPSHIP)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158724" id="158724">CVE-2005-0210 dst leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158814" id="158814">FEAT: [RHEL3 U6] add PCI_VENDOR_ID_NEC to megaraid subsysvid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158817" id="158817">Adding 3pardata to the scsi device whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158877" id="158877">[RHEL3 U4] setsockopt SO_RCVTIMEO call fails from a 32 bit binary running on a  x86_64 system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158880" id="158880">[Patch] RHEL3 U6: lower severity of blk: queue xxxx printks (~MF)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159045" id="159045">CVE-2005-1767 x86_64 crashes from context switches on stk-seg-fault stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159300" id="159300">FEAT:  RHEL3 U6:  Update e100 driver to later than v.3.4.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159330" id="159330">x86_64 kernel stops allocating memory too early when overcommit_memory set to strict</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159420" id="159420">RHEL3 U6: ESB2 support (PATA, SATA, USB, SMBUS, LPC, Audio and AHCI)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159790" id="159790">ptrace changes to registers during ia32 syscall tracing stop are lost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159814" id="159814">x86-64 PTRACE_SETOPTIONS does not support most option flags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159823" id="159823">CVE-2005-1761 local user can use ptrace to crash system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159915" id="159915">CVE-2005-1762 x86_64 crash (ptrace-canonical)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159917" id="159917">CVE-2005-0756 x86_64 crash (ptrace-check-segment)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159938" id="159938">Diskdump disk controllers support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159979" id="159979">Fix dangling pointer in acpi_pci_root_add()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159989" id="159989">[RHEL3][PATCH] suppress medum-not-present messages from idefloppy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159991" id="159991">[taroon patch] fix for indefinite postponement under __alloc_pages()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159992" id="159992">Add docs detailing which drivers support netconsole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159993" id="159993">CVE-2005-2553 x86_64 fix for 32-bit ptrace find_target() oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160093" id="160093">[RHEL3][PATCH] suppress medum-not-present messages from idefloppy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160199" id="160199">CVE-2005-1768 64bit execve() race leads to buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160392" id="160392">Memory Leak in autofs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160400" id="160400">The AHCI driver was incorrectly resetting the hardware on error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160495" id="160495">RHEL 3 U5 code base contains duplicate USB ESSENTIAL_REALITY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160664" id="160664">cable link state ignored on ethernet card (b44).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160752" id="160752">accounting of SETITIMER_PROF inaccurate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160799" id="160799">Kernel panic: pci_map_single: high address but no IOMMU.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160820" id="160820">nVidia driver requires upstream  page_attr patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161097" id="161097">CRM 565876: samba-3.0.8pre1-smbmnt.patch to fix smbmount UID wraparound bug for RHEL3 Samba packages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161238" id="161238">superbh function causing a server to crash when Veritas Volume Manager Modules for VxVM 4.0 are loaded.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161657" id="161657">iscsi_sfnet driver does not calculate ConnFailTimeout correctly when greater than 15 secs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161957" id="161957">CRM: 507606 / short freezes on Informix server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161986" id="161986">RHEL3 U5 panic in kmem_cache_grow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162103" id="162103">add SGI scsi devices to list in scsi_scan.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162603" id="162603">dpt_i2o driver oopses on insmod in U5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163152" id="163152">Initiator does not retry login on target error when PortalFailover is disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164074" id="164074">Placeholder for 2.4.x SATA update 20050723-1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164185" id="164185">rpm install of -33.EL on ia64 gets unresolved pm_power_off symbol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164226" id="164226">User-mode program run on IA64 AS 3.0 causes system to crash due to invalid stack pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164819" id="164819">[RHEL3U6] diskdump - scsi dump fails with module CRC error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165467" id="165467">[RHEL3 U6] Fix to update openipmi drivers for Dell 8G server line (MUSTFIX)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165565" id="165565">CVE-2005-2456 IPSEC overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165739" id="165739">LTC14996-IPMI driver is broken on multiple platforms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165841" id="165841">[RHEL3U6] diskdump fails with machine check error on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165850" id="165850">Disable FAN processing in Emulex lpfc driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165866" id="165866">Add Invista to RHEL 3 SCSI Whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165993" id="165993">NFS deadlock when multiple processes creating/deleting a file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166066" id="166066">IBM TapeLibrary 3583</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166132" id="166132">CVE-2005-2555 IPSEC lacks restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166172" id="166172">Kernel crash on 2.4.21-34 base due to kiobuf_init() setting the initialized state when expand_kiobuf() was not called.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166329" id="166329">CVE-2005-2490 sendmsg compat stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167047" id="167047">cciss, add pci id for P400</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167222" id="167222">[BETA RHEL3 U6] kernel panic while booting numa=off on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167265" id="167265">drivers/addon/lpfc/lpfcdfc/Makefile change causing intermittent build failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167369" id="167369">[RHEL3] cosmetic change to IPMI drivers to update version revision number</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663004" comment="kernel-source is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663002" comment="kernel is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663006" comment="kernel-doc is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663012" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663016" comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663018" comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663008" comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050663014" comment="kernel-smp is earlier than 0:2.4.21-37.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050670" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:670: xpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:670-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-670.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

A flaw was discovered in Xpdf in that an attacker could construct a
carefully crafted PDF file that would cause Xpdf to consume all available
disk space in /tmp when opened. The Common Vulnerabilities and Exposures
project assigned the name CAN-2005-2097 to this issue.

Note this issue does not affect the version of Xpdf in Red Hat Enterprise
Linux 3 or 2.1.

Users of xpdf should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163918" id="163918">CAN-2005-2097 xpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050670002" comment="xpdf is earlier than 1:3.00-11.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050671" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:671: kdegraphics security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:671-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-671.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A flaw was discovered in kpdf.  An attacker could construct a carefully
crafted PDF file that would cause kpdf to consume all available disk space
in /tmp when opened. The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-2097 to this issue.

Note this issue does not affect Red Hat Enterprise Linux 3 or 2.1.

Users of kpdf should upgrade to these updated packages, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163925" id="163925">CAN-2005-2097 kpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050671002" comment="kdegraphics is earlier than 7:3.3.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050671004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050673" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:673: binutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:673-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-673.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
    
    <description>Binutils is a collection of utilities used for the creation of executable
code. A number of bugs were found in various binutils tools.  

If a user is tricked into processing a specially crafted executable with
utilities such as readelf, size, strings, objdump, or nm, it may allow the
execution of arbitrary code as the user. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-1704 to
this issue.

In addition, the following bugs have been fixed:

-- by default issue an error if IA-64 hint@pause instruction is
   put into the B slot, add assembler command line switch to
   override this behaviour
-- fix linker's --emit-relocs with .gnu.warning.* section symbols
-- fix gprof on 64-bit ppc binaries and libraries
-- fix gas mapping of register names to dwarf2 register numbers
   in CFI directives

All users of binutils should upgrade to this updated package, which
contains patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
                <bugzilla href="http://bugzilla.redhat.com/159894" id="159894">CAN-2005-1704 Integer overflow in the Binary File Descriptor (BFD) library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162545" id="162545">wrong dwarf register numbers generated</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050673002" comment="binutils is earlier than 0:2.15.92.0.2-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050659003" comment="binutils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050674" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:674: perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:674-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-674.html" />
          <reference source="CVE" ref_id="CVE-2005-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0448.html" />
    
    <description>Perl is a high-level programming language commonly used for system     
administration utilities and Web programming.    

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module
removed directory trees. If a local user has write permissions to a
subdirectory within the tree being removed by File::Path::rmtree, it is
possible for them to create setuid binary files. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0448
to this issue.    

This update also addresses the following issues:

-- Perl interpreter caused a segmentation fault when environment    
changes occurred during runtime.

-- Code in lib/FindBin contained a regression that caused problems with  
 MRTG software package.

-- Perl incorrectly declared it provides an FCGI interface where it in fact
  did not.    

Users of Perl are advised to upgrade to these updated packages, which 
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0448.html">CVE-2005-0448</cve>
                <bugzilla href="http://bugzilla.redhat.com/127023" id="127023">perl fails "lib/FindBin" test (breaks MRTG)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/148848" id="148848">Packing fault with perl and FCGI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155888" id="155888">perl-suidperl package has an extra .1 release suffix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157694" id="157694">CAN-2005-0448 perl File::Path.pm rmtree race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050674004" comment="perl-suidperl is earlier than 3:5.8.5-16.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050674002" comment="perl is earlier than 3:5.8.5-16.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050685" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:685: mysql security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:685-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-685.html" />
          <reference source="CVE" ref_id="CVE-2005-1636" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1636.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld)
and many different client programs and libraries.

An insecure temporary file handling bug was found in the mysql_install_db
script. It is possible for a local user to create specially crafted files
in /tmp which could allow them to execute arbitrary SQL commands during
database installation. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1636 to this issue.

These packages update mysql to version 4.1.12, fixing a number of problems.
Also, support for SSL-encrypted connections to the database server is now
provided.

All users of mysql are advised to upgrade to these updated packages.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1636.html">CVE-2005-1636</cve>
                <bugzilla href="http://bugzilla.redhat.com/158688" id="158688">CAN-2005-1636 mysql insecure temporary file creation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163694" id="163694">Parser issue with subqueries involving unions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685002" comment="mysql is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685004" comment="mysql-server is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334005" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685008" comment="mysql-bench is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334009" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050685006" comment="mysql-devel is earlier than 0:4.1.12-3.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050334007" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050687" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:687: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:687-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-687.html" />
          <reference source="CVE" ref_id="CVE-2005-2360" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2360.html" />
          <reference source="CVE" ref_id="CVE-2005-2361" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2361.html" />
          <reference source="CVE" ref_id="CVE-2005-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2362.html" />
          <reference source="CVE" ref_id="CVE-2005-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2363.html" />
          <reference source="CVE" ref_id="CVE-2005-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2364.html" />
          <reference source="CVE" ref_id="CVE-2005-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2365.html" />
          <reference source="CVE" ref_id="CVE-2005-2366" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2366.html" />
          <reference source="CVE" ref_id="CVE-2005-2367" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2367.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-2360, CAN-2005-2361,
CAN-2005-2362, CAN-2005-2363, CAN-2005-2364, CAN-2005-2365, CAN-2005-2366,
and CAN-2005-2367 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.12 which is not vulnerable to these issues.

Note: To reduce the risk of future vulnerabilities in Ethereal, the
ethereal and tethereal programs in this update have been compiled as
Position Independant Executables (PIE) for Red Hat Enterprise Linux 3 and
4.  In addition FORTIFY_SOURCE has been enabled for Red Hat Enterprise
Linux 4 packages to provide compile time and runtime buffer checks.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-10" />
        <updated date="2005-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2360.html">CVE-2005-2360</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2361.html">CVE-2005-2361</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2362.html">CVE-2005-2362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2363.html">CVE-2005-2363</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2364.html">CVE-2005-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2365.html">CVE-2005-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2366.html">CVE-2005-2366</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2367.html">CVE-2005-2367</cve>
                <bugzilla href="http://bugzilla.redhat.com/164243" id="164243">CAN-2005-2360 Multiple ethereal flaws (CAN-2005-2361 CAN-2005-2362 CAN-2005-2363 CAN-2005-2364 CAN-2005-2365 CAN-2005-2366 CAN-2005-2367)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687004" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687002" comment="ethereal is earlier than 0:0.10.12-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687008" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050687007" comment="ethereal is earlier than 0:0.10.12-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050706" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:706: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:706-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-706.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer for
UNIX(R) operating systems.

When processing a PDF file, bounds checking was not correctly performed on
some fields.  This could cause the pdftops filter (running as user "lp") to
crash.  The Common Vulnerabilities and Exposures project has assigned the
name CAN-2005-2097 to this issue.

All users of CUPS should upgrade to these erratum packages, which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-09" />
        <updated date="2005-08-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/164510" id="164510">CAN-2005-2097 pdf flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706004" comment="cups-devel is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706006" comment="cups-libs is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706002" comment="cups is earlier than 1:1.1.17-13.3.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050706009" comment="cups is earlier than 1:1.1.22-0.rc1.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050708" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:708: gpdf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:708-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-708.html" />
          <reference source="CVE" ref_id="CVE-2005-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2097.html" />
    
    <description>The gpdf package is an GNOME based viewer for Portable Document Format
(PDF) files.

Marcus Meissner reported a flaw in gpdf.  An attacker could construct a
carefully crafted PDF file that would cause gpdf to consume all available
disk space in /tmp when opened. The Common Vulnerabilities and Exposures
project assigned the name CAN-2005-2097 to this issue.

Note that this issue does not affect the version of gpdf in Red Hat
Enterprise Linux 3 or 2.1.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-10" />
        <updated date="2005-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2097.html">CVE-2005-2097</cve>
                <bugzilla href="http://bugzilla.redhat.com/163920" id="163920">CAN-2005-2097 gpdf DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050708002" comment="gpdf is earlier than 0:2.8.2-4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050709" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:709: gdb security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:709-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-709.html" />
          <reference source="CVE" ref_id="CVE-2005-1704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1704.html" />
          <reference source="CVE" ref_id="CVE-2005-1705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-1705.html" />
    
    <description>GDB, the GNU debugger, allows debugging of programs written in C, C++,
and other languages by executing them in a controlled fashion, then
printing their data.

Several integer overflow bugs were found in gdb. If a user is tricked
into processing a specially crafted executable file, it may allow the
execution of arbitrary code as the user running gdb. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-1704 to this issue.

A bug was found in the way gdb loads .gdbinit files. When a user executes
gdb, the local directory is searched for a .gdbinit file which is then
loaded. It is possible for a local user to execute arbitrary commands as
the victim running gdb by placing a malicious .gdbinit file in a location
where gdb may be run. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-1705 to this issue.

This updated package also addresses the following issues:

- GDB on ia64 had previously implemented a bug fix to work-around a kernel
problem when creating a core file via gcore.  The bug fix caused a
significant slow-down of gcore.

- GDB on ia64 issued an extraneous warning when gcore was used.

- GDB on ia64 could not backtrace over a sigaltstack.

- GDB on ia64 could not successfully do an info frame for a signal trampoline.

- GDB on AMD64 and Intel EM64T had problems attaching to a 32-bit process.

- GDB on AMD64 and Intel EM64T was not properly handling threaded watchpoints.

- GDB could not build with gcc4 when -Werror flag was set.

- GDB had problems printing inherited members of C++ classes.

- A few updates from mainline sources concerning Dwarf2 partial die in
cache support, follow-fork support, interrupted syscall support, and
DW_OP_piece read support.

All users of gdb should upgrade to this updated package, which resolves
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-05" />
        <updated date="2005-10-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1704.html">CVE-2005-1704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-1705.html">CVE-2005-1705</cve>
                <bugzilla href="http://bugzilla.redhat.com/158680" id="158680">CAN-2005-1704 Integer overflow in gdb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158684" id="158684">CAN-2005-1705 gdb arbitrary command execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160339" id="160339">GDB fails to correctly report frame information</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050709002" comment="gdb is earlier than 0:6.3.0.0-1.63" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050709003" comment="gdb is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050743" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:743: netpbm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:743-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-743.html" />
          <reference source="CVE" ref_id="CVE-2005-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2471.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts PostScript files into PBM, PGM
or PPM files.  An attacker could create a carefully crafted PostScript file
in such a way that it could execute arbitrary commands when the
file is processed by a victim using pstopnm.  The Common Vulnerabilities
and Exposures project assigned the name CAN-2005-2471 to this issue.

All users of netpbm should upgrade to the updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-22" />
        <updated date="2005-08-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2471.html">CVE-2005-2471</cve>
                <bugzilla href="http://bugzilla.redhat.com/165354" id="165354">CAN-2005-2471 netpbm should use the -dSAFER option when calling Ghostscript</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743002" comment="netpbm is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743004" comment="netpbm-devel is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743006" comment="netpbm-progs is earlier than 0:9.24-11.30.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743009" comment="netpbm is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743010" comment="netpbm-devel is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050743011" comment="netpbm-progs is earlier than 0:10.25-2.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050745" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:745: vim security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:745-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-745.html" />
          <reference source="CVE" ref_id="CVE-2005-2368" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2368.html" />
    
    <description>VIM (VIsual editor iMproved) is a version of the vi editor.   

A bug was found in the way VIM processes modelines. If a user with
modelines enabled opens a text file with a carefully crafted modeline,
arbitrary commands may be executed as the user running VIM. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2368
to this issue.
 
Users of VIM are advised to upgrade to these updated packages, which
resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-22" />
        <updated date="2005-08-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2368.html">CVE-2005-2368</cve>
                <bugzilla href="http://bugzilla.redhat.com/164279" id="164279">CAN-2005-2368 vim modeline arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745006" comment="vim-minimal is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745002" comment="vim is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745004" comment="vim-common is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745015" comment="vim-minimal is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745013" comment="vim is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745017" comment="vim-X11 is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745014" comment="vim-common is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050745016" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050748" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:748: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:748-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-748.html" />
          <reference source="CVE" ref_id="CVE-2005-2498" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2498.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A bug was discovered in the PEAR XML-RPC Server package included in PHP. If
a PHP script is used which implements an XML-RPC Server using the PEAR
XML-RPC package, then it is possible for a remote attacker to construct an
XML-RPC request which can cause PHP to execute arbitrary PHP commands as
the 'apache' user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2498 to this issue.

When using the default SELinux "targeted" policy on Red Hat Enterprise
Linux 4, the impact of this issue is reduced since the scripts executed by
PHP are constrained within the httpd_sys_script_t security context.

Users of PHP should upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-08-19" />
        <updated date="2005-08-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2498.html">CVE-2005-2498</cve>
                <bugzilla href="http://bugzilla.redhat.com/165846" id="165846">CAN-2005-2498 PHP PEAR:XMLRPC eval code injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748014" comment="php-odbc is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748010" comment="php-mysql is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748002" comment="php is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748012" comment="php-pgsql is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748004" comment="php-devel is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748006" comment="php-imap is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748008" comment="php-ldap is earlier than 0:4.3.2-25.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748036" comment="php-gd is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748025" comment="php-odbc is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748023" comment="php-mysql is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748017" comment="php is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748030" comment="php-xmlrpc is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748032" comment="php-mbstring is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748024" comment="php-pgsql is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748018" comment="php-devel is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748034" comment="php-ncurses is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748026" comment="php-snmp is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748021" comment="php-imap is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748019" comment="php-pear is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748028" comment="php-domxml is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050748022" comment="php-ldap is earlier than 0:4.3.9-3.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050751" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:751: openldap and nss_ldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:751-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-751.html" />
          <reference source="CVE" ref_id="CVE-2004-0823" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0823.html" />
          <reference source="CVE" ref_id="CVE-2005-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2069.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

The nss_ldap module is an extension for use with GNU libc which allows
applications to, without internal modification, consult a directory service
using LDAP to supplement information that would be read from local files
such as /etc/passwd, /etc/group, and /etc/shadow.

A bug was found in the way OpenLDAP, nss_ldap, and pam_ldap refer LDAP
servers. If a client connection is referred to a different server, it is
possible that the referred connection will not be encrypted even if the
client has "ssl start_tls" in its ldap.conf file. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2069
to this issue.

A bug was also found in the way certain OpenLDAP authentication schemes
store hashed passwords. A remote attacker could re-use a hashed password to
gain access to unauthorized resources. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-0823 to this issue.

All users of OpenLDAP and nss_ldap are advised to upgrade to these updated
packages, which contain backported fixes that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2005-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0823.html">CVE-2004-0823</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2069.html">CVE-2005-2069</cve>
                <bugzilla href="http://bugzilla.redhat.com/156386" id="156386">CAN-2004-0823 openldap hashed password re-use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162482" id="162482">CAN-2005-2069 openldap password disclosure issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751004" comment="openldap-devel is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751005" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751008" comment="openldap-clients is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751009" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751002" comment="openldap is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751006" comment="openldap-servers is earlier than 0:2.0.27-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751007" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050751010" comment="nss_ldap is earlier than 0:207-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751011" comment="nss_ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050756" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:756: cvs security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:756-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-756.html" />
          <reference source="CVE" ref_id="CVE-2005-2693" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2693.html" />
    
    <description>CVS (Concurrent Version System) is a version control system.

An insecure temporary file usage was found in the cvsbug program.  It is
possible that a local user could leverage this issue to execute arbitrary
instructions as the user running cvsbug.  The Common Vulnerabilities and
Exposures project assigned the name CAN-2005-2693 to this issue.

All users of cvs should upgrade to this updated package, which includes a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-06" />
        <updated date="2005-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2693.html">CVE-2005-2693</cve>
                <bugzilla href="http://bugzilla.redhat.com/166365" id="166365">CAN-2005-2693 CVS temporary file issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050756002" comment="cvs is earlier than 0:1.11.2-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050756005" comment="cvs is earlier than 0:1.11.17-8.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050387003" comment="cvs is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050761" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:761: pcre security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:761-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-761.html" />
          <reference source="CVE" ref_id="CVE-2005-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2491.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

An integer overflow flaw was found in PCRE, triggered by a maliciously
crafted regular expression.  On systems that accept arbitrary regular
expressions from untrusted users, this could be exploited to execute
arbitrary code with the privileges of the application using the library.
The Common Vulnerabilities and Exposures project assigned the name
CAN-2005-2491 to this issue.

The security impact of this issue varies depending on the way that
applications make use of PCRE.  For example, the Apache web server uses the
system PCRE library in order to parse regular expressions, but this flaw
would only allow a user who already has the ability to write .htaccess
files to gain 'apache' privileges.  For applications supplied with Red Hat
Enterprise Linux, a maximum security impact of moderate has been assigned.

Users should update to these erratum packages that contain a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-08" />
        <updated date="2005-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2491.html">CVE-2005-2491</cve>
                <bugzilla href="http://bugzilla.redhat.com/166330" id="166330">CAN-2005-2491 PCRE heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761004" comment="pcre-devel is earlier than 0:3.9-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761002" comment="pcre is earlier than 0:3.9-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761008" comment="pcre-devel is earlier than 0:4.5-3.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050761007" comment="pcre is earlier than 0:4.5-3.2.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050761003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050766" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:766: squid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:766-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-766.html" />
          <reference source="CVE" ref_id="CVE-2004-2479" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2479.html" />
          <reference source="CVE" ref_id="CVE-2005-2794" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2794.html" />
          <reference source="CVE" ref_id="CVE-2005-2796" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2796.html" />
    
    <description>Squid is a full-featured Web proxy cache.

A bug was found in the way Squid displays error messages. A remote attacker
could submit a request containing an invalid hostname which would result in
Squid displaying a previously used error message. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-2479 to this issue.

Two denial of service bugs were found in the way Squid handles malformed
requests. A remote attacker could submit a specially crafted request to
Squid that would cause the server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the names CAN-2005-2794 and
CAN-2005-2796 to these issues.

Please note that CAN-2005-2796 does not affect Red Hat Enterprise Linux 2.1

Users of Squid should upgrade to this updated package that contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-15" />
        <updated date="2005-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2479.html">CVE-2004-2479</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2794.html">CVE-2005-2794</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2796.html">CVE-2005-2796</cve>
                <bugzilla href="http://bugzilla.redhat.com/166520" id="166520">CAN-2004-2479 squid information disclosure issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167413" id="167413">CAN-2005-2794 Multiple squid DoS issues (CAN-2005-2796)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050766002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050766005" comment="squid is earlier than 7:2.5.STABLE6-3.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050767" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:767: openldap and nss_ldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:767-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-767.html" />
          <reference source="CVE" ref_id="CVE-2005-2069" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2069.html" />
          <reference source="CVE" ref_id="CVE-2005-2641" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2641.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

The nss_ldap module is an extension for use with GNU libc which allows
applications to, without internal modification, consult a directory service
using LDAP to supplement information that would be read from local files
such as /etc/passwd, /etc/group, and /etc/shadow.

A bug was found in the way OpenLDAP, nss_ldap, and pam_ldap refer LDAP
servers. If a client connection is referred to a different server, it is
possible that the referred connection will not be encrypted even if the
client has "ssl start_tls" in its ldap.conf file. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2005-2069
to this issue.

A bug was found in the way the pam_ldap module processed certain failure
messages. If the server includes supplemental data in an authentication
failure result message, but the data does not include any specific error
code, the pam_ldap module would proceed as if the authentication request
had succeeded, and authentication would succeed. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-2641 to this issue. 

Additionally the following issues are corrected in this erratum.

- The OpenLDAP upgrading documentation has been updated.

- Fix a database deadlock locking issue.

- A fix where slaptest segfaults on exit after successful check.

- The library libslapd_db-4.2.so is now located in an
  architecture-dependent directory.

- The LDAP client no longer enters an infinite loop when the server returns
  a reference to itself.

- The pam_ldap module adds the ability to check user passwords using a
  directory server to PAM-aware applications.

- The directory server can now include supplemental information regarding
  the state of the user's account if a client indicates that it supports
  such a feature.

All users of OpenLDAP and nss_ldap are advised to upgrade to these updated
packages, which contain backported fixes that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2005-10-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2069.html">CVE-2005-2069</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2641.html">CVE-2005-2641</cve>
                <bugzilla href="http://bugzilla.redhat.com/159151" id="159151">Authconfig update creates a problem with OpenLDAP server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162482" id="162482">CAN-2005-2069 openldap password disclosure issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166163" id="166163">CAN-2005-2641 pam_ldap policy vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767004" comment="openldap-devel is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751005" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767010" comment="openldap-clients is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751009" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767008" comment="openldap-servers-sql is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050767009" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767012" comment="compat-openldap is earlier than 0:2.1.30-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050767013" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767002" comment="openldap is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767006" comment="openldap-servers is earlier than 0:2.2.13-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751007" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050767014" comment="nss_ldap is earlier than 0:226-10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050751011" comment="nss_ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050768" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:768: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:768-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-768.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox processes certain international domain
names. An attacker could create a specially crafted HTML file, which when
viewed by the victim would cause Firefox to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2871 to this issue. 

Users of Firefox are advised to upgrade to this updated package that
contains a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-09" />
        <updated date="2005-09-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/167930" id="167930">CAN-2005-2871 Firefox buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050768002" comment="firefox is earlier than 0:1.0.6-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050769" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:769: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:769-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-769.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla processes certain international domain
names. An attacker could create a specially crafted HTML file, which when
viewed by the victim would cause Mozilla to crash or possibly execute
arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2871 to this issue. 

Users of Mozilla are advised to upgrade to this updated package that
contains a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-09" />
        <updated date="2005-09-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/167934" id="167934">CAN-2005-2871 Mozilla buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769018" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769014" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769016" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769010" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769002" comment="mozilla is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769020" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769006" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769004" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769012" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769008" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769031" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769029" comment="mozilla-mail is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769030" comment="mozilla-chat is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769027" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769023" comment="mozilla is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769032" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769025" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769024" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769028" comment="mozilla-devel is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050769026" comment="mozilla-nss is earlier than 37:1.7.10-1.4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050771" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:771: wget security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:771-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-771.html" />
          <reference source="CVE" ref_id="CVE-2004-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1487.html" />
          <reference source="CVE" ref_id="CVE-2004-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-1488.html" />
          <reference source="CVE" ref_id="CVE-2004-2014" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2014.html" />
    
    <description>GNU Wget is a file retrieval utility that can use either the HTTP or        
FTP protocols.       

A bug was found in the way wget writes files to the local disk. If a
malicious local user has write access to the directory wget is saving a
file into, it is possible to overwrite files that the user running wget
has write access to. (CAN-2004-2014)

A bug was found in the way wget filters redirection URLs. It is possible
for a malicious Web server to overwrite files the user running wget has
write access to. Note: in order for this attack to succeed the local
DNS would need to resolve ".." to an IP address, which is an unlikely
situation.  (CAN-2004-1487)

A bug was found in the way wget displays HTTP response codes. It is
possible that a malicious web server could inject a specially crafted
terminal escape sequence capable of misleading the user running wget.
(CAN-2004-1488)
   
Users should upgrade to this updated package, which contains a version of
wget that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1487.html">CVE-2004-1487</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-1488.html">CVE-2004-1488</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2014.html">CVE-2004-2014</cve>
                <bugzilla href="http://bugzilla.redhat.com/144214" id="144214">CAN-2004-1487 Several wget vulnerabilities (CAN-2004-1488)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157498" id="157498">CAN-2004-2014 wget symlink race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165782" id="165782">wget man page incomplete</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771002" comment="wget is earlier than 0:1.10.1-1.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771005" comment="wget is earlier than 0:1.10.1-2.4E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050772" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:772: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:772-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-772.html" />
          <reference source="CVE" ref_id="CVE-2005-2874" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2874.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A bug was found in the way CUPS processes malformed HTTP requests. It is
possible for a remote user capable of connecting to the CUPS daemon to
issue a malformed HTTP GET request that causes CUPS to enter an
infinite loop. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-2874 to this issue.

Two small bugs have also been fixed in this update.  A signal handling
problem has been fixed that could occasionally cause the scheduler to stop
when told to reload.  A problem with tracking open file descriptors under
certain specific circumstances has also been fixed.

All users of CUPS should upgrade to these erratum packages, which contain a
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2874.html">CVE-2005-2874</cve>
                <bugzilla href="http://bugzilla.redhat.com/164641" id="164641">[PATCH] cupsd segfault when SIGCHLD received</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164642" id="164642">Cupsd hangs on reading pipe with recycled file descriptor.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168072" id="168072">CAN-2005-2874 Malformed HTTP Request URL denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050772002" comment="cups is earlier than 1:1.1.22-0.rc1.9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050782" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:782: util-linux and mount security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:782-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-782.html" />
          <reference source="CVE" ref_id="CVE-2005-2876" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2876.html" />
          <reference source="CVE" ref_id="CVE-2001-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2001-1494.html" />
    
    <description>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function.

The mount package contains the mount, umount, swapon and swapoff programs.

A bug was found in the way the umount command is executed by normal users.
It may be possible for a user to gain elevated privileges if the user is
able to execute the "umount -r" command on a mounted file system. The
file system will be re-mounted only with the "readonly" flag set, clearing
flags such as "nosuid" and "noexec". The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2876 to
this issue.

This update also fixes a hardlink bug in the script command for Red Hat
Enterprise Linux 2.1. If a local user places a hardlinked file named
"typescript" in a directory they have write access to, the file will be
overwritten if the user running script has write permissions to the
destination file. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2001-1494 to this issue.

All users of util-linux and mount should upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2876.html">CVE-2005-2876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2001-1494.html">CVE-2001-1494</cve>
                <bugzilla href="http://bugzilla.redhat.com/161337" id="161337">CAN-2001-1494 hardlink vulnerability in 'script' command</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168206" id="168206">CAN-2005-2876 umount unsafe -r usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168209" id="168209">CAN-2005-2876 umount unsafe -r usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782002" comment="util-linux is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782004" comment="mount is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782005" comment="mount is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050782006" comment="losetup is earlier than 0:2.11y-31.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782007" comment="losetup is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782009" comment="util-linux is earlier than 0:2.12a-16.EL4.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050782003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050785" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:785: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:785-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-785.html" />
          <reference source="CVE" ref_id="CVE-2005-2701" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2701.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-2968" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2968.html" />
          <reference source="CVE" ref_id="CVE-2005-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3089.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A bug was found in the way Firefox processes XBM image files. If a user
views a specially crafted XBM file, it becomes possible to execute
arbitrary code as the user running Firefox. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2701 to
this issue.

A bug was found in the way Firefox processes certain Unicode
sequences. It may be possible to execute arbitrary code as the user running
Firefox if the user views a specially crafted Unicode sequence. (CAN-2005-2702)

A bug was found in the way Firefox makes XMLHttp requests. It is possible
that a malicious web page could leverage this flaw to exploit other proxy
or server flaws from the victim's machine. It is also possible that this
flaw could be leveraged to send XMLHttp requests to hosts other than the
originator; the default behavior of the browser is to disallow this.
(CAN-2005-2703)

A bug was found in the way Firefox implemented its XBL interface. It may be
possible for a malicious web page to create an XBL binding in such a way
that would allow arbitrary JavaScript execution with chrome permissions.
Please note that in Firefox 1.0.6 this issue is not directly exploitable
and will need to leverage other unknown exploits. (CAN-2005-2704)

An integer overflow bug was found in Firefox's JavaScript engine. Under
favorable conditions, it may be possible for a malicious web page to
execute arbitrary code as the user running Firefox. (CAN-2005-2705)

A bug was found in the way Firefox displays about: pages. It is possible
for a malicious web page to open an about: page, such as about:mozilla, in
such a way that it becomes possible to execute JavaScript with chrome
privileges. (CAN-2005-2706)

A bug was found in the way Firefox opens new windows. It is possible for a
malicious web site to construct a new window without any user interface
components, such as the address bar and the status bar. This window could
then be used to mislead the user for malicious purposes. (CAN-2005-2707)

A bug was found in the way Firefox processes URLs passed to it on the
command line. If a user passes a malformed URL to Firefox, such as clicking
on a link in an instant messaging program, it is possible to execute
arbitrary commands as the user running Firefox. (CAN-2005-2968)

Users of Firefox are advised to upgrade to this updated package that
contains Firefox version 1.0.7 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-22" />
        <updated date="2005-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2701.html">CVE-2005-2701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2968.html">CVE-2005-2968</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3089.html">CVE-2005-3089</cve>
                <bugzilla href="http://bugzilla.redhat.com/168527" id="168527">CAN-2005-2701 Multiple Firefox issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168740" id="168740">CAN-2005-2968 Firefox improper command line URL sanitization</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050785002" comment="firefox is earlier than 0:1.0.7-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050176003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050788" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:788: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:788-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-788.html" />
          <reference source="CVE" ref_id="CVE-2005-2629" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2629.html" />
          <reference source="CVE" ref_id="CVE-2005-2710" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2710.html" />
          <reference source="CVE" ref_id="CVE-2005-2922" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2922.html" />
    
    <description>HelixPlayer is a media player.

A format string bug was discovered in the way HelixPlayer processes RealPix
(.rp) files. It is possible for a malformed RealPix file to execute
arbitrary code as the user running HelixPlayer. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2710
to this issue.

All users of HelixPlayer are advised to upgrade to this updated package,
which contains HelixPlayer version 10.0.6 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-27" />
        <updated date="2005-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2629.html">CVE-2005-2629</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2710.html">CVE-2005-2710</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2922.html">CVE-2005-2922</cve>
                <bugzilla href="http://bugzilla.redhat.com/168078" id="168078">CAN-2005-2710 HelixPlayer Format String Flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050788002" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050271003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050789" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:789: mozilla security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:789-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-789.html" />
          <reference source="CVE" ref_id="CVE-2005-2701" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2701.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3089.html" />
    
    <description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

A bug was found in the way Mozilla processes XBM image files. If a user
views a specially crafted XBM file, it becomes possible to execute
arbitrary code as the user running Mozilla. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-2701 to
this issue.

A bug was found in the way Mozilla processes certain Unicode
sequences. It may be possible to execute arbitrary code as the user running
Mozilla, if the user views a specially crafted Unicode sequence.
(CAN-2005-2702)

A bug was found in the way Mozilla makes XMLHttp requests. It is possible
that a malicious web page could leverage this flaw to exploit other proxy
or server flaws from the victim's machine. It is also possible that this
flaw could be leveraged to send XMLHttp requests to hosts other than the
originator; the default behavior of the browser is to disallow this.
(CAN-2005-2703)

A bug was found in the way Mozilla implemented its XBL interface. It may be
possible for a malicious web page to create an XBL binding in a way
that would allow arbitrary JavaScript execution with chrome permissions.
Please note that in Mozilla 1.7.10 this issue is not directly exploitable
and would need to leverage other unknown exploits. (CAN-2005-2704)

An integer overflow bug was found in Mozilla's JavaScript engine. Under
favorable conditions, it may be possible for a malicious web page to
execute arbitrary code as the user running Mozilla. (CAN-2005-2705)

A bug was found in the way Mozilla displays about: pages. It is possible
for a malicious web page to open an about: page, such as about:mozilla, in
such a way that it becomes possible to execute JavaScript with chrome
privileges. (CAN-2005-2706)

A bug was found in the way Mozilla opens new windows. It is possible for a
malicious web site to construct a new window without any user interface
components, such as the address bar and the status bar. This window could
then be used to mislead the user for malicious purposes. (CAN-2005-2707)

Users of Mozilla are advised to upgrade to this updated package that
contains Mozilla version 1.7.12 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-22" />
        <updated date="2005-09-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2701.html">CVE-2005-2701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3089.html">CVE-2005-3089</cve>
                <bugzilla href="http://bugzilla.redhat.com/168525" id="168525">CAN-2005-2701 Multiple Mozilla issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789018" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789014" comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789016" comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789010" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789002" comment="mozilla is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789020" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789006" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789004" comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789012" comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789008" comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789031" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789029" comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789030" comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789027" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789023" comment="mozilla is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789032" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789025" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789024" comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789028" comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789026" comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789033" comment="devhelp is earlier than 0:0.9.2-2.4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335023" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050789035" comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050335025" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050791" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:791: thunderbird security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:791-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-791.html" />
          <reference source="CVE" ref_id="CVE-2005-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2871.html" />
          <reference source="CVE" ref_id="CVE-2005-2702" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2702.html" />
          <reference source="CVE" ref_id="CVE-2005-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2703.html" />
          <reference source="CVE" ref_id="CVE-2005-2704" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2704.html" />
          <reference source="CVE" ref_id="CVE-2005-2705" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2705.html" />
          <reference source="CVE" ref_id="CVE-2005-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2706.html" />
          <reference source="CVE" ref_id="CVE-2005-2707" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2707.html" />
          <reference source="CVE" ref_id="CVE-2005-2968" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2968.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A bug was found in the way Thunderbird processes certain international
domain names. An attacker could create a specially crafted HTML mail, which
when viewed by the victim would cause Thunderbird to crash or possibly
execute arbitrary code. Thunderbird as shipped with Red Hat Enterprise
Linux 4 must have international domain names enabled by the user in order
to be vulnerable to this issue. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2871 to this issue.

A bug was found in the way Thunderbird processes certain Unicode sequences.
It may be possible to execute arbitrary code as the user running
Thunderbird if the user views a specially crafted HTML mail containing
Unicode sequences. (CAN-2005-2702)

A bug was found in the way Thunderbird makes XMLHttp requests. It is
possible that a malicious HTML mail could leverage this flaw to exploit
other proxy or server flaws from the victim's machine. It is also possible
that this flaw could be leveraged to send XMLHttp requests to hosts other
than the originator; the default behavior of Thunderbird is to disallow
such actions. (CAN-2005-2703)

A bug was found in the way Thunderbird implemented its XBL interface. It
may be possible for a malicious HTML mail to create an XBL binding in such
a way that would allow arbitrary JavaScript execution with chrome
permissions. Please note that in Thunderbird 1.0.6 this issue is not
directly exploitable and will need to leverage other unknown exploits.
(CAN-2005-2704)

An integer overflow bug was found in Thunderbird's JavaScript engine. Under
favorable conditions, it may be possible for a malicious mail message to
execute arbitrary code as the user running Thunderbird. Please note that
JavaScript support is disabled by default in Thunderbird. (CAN-2005-2705)

A bug was found in the way Thunderbird displays about: pages. It is
possible for a malicious HTML mail to open an about: page, such as
about:mozilla, in such a way that it becomes possible to execute JavaScript
with chrome privileges. (CAN-2005-2706)

A bug was found in the way Thunderbird opens new windows. It is possible
for a malicious HTML mail to construct a new window without any user
interface components, such as the address bar and the status bar. This
window could then be used to mislead the user for malicious purposes.
(CAN-2005-2707)

A bug was found in the way Thunderbird processes URLs passed to it on the
command line. If a user passes a malformed URL to Thunderbird, such as
clicking on a link in an instant messaging program, it is possible to
execute arbitrary commands as the user running Thunderbird. (CAN-2005-2968) 

Users of Thunderbird are advised to upgrade to this updated package, which
contains Thunderbird version 1.0.7 and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-06" />
        <updated date="2005-10-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2871.html">CVE-2005-2871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2702.html">CVE-2005-2702</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2703.html">CVE-2005-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2704.html">CVE-2005-2704</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2705.html">CVE-2005-2705</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2706.html">CVE-2005-2706</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2707.html">CVE-2005-2707</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2968.html">CVE-2005-2968</cve>
                <bugzilla href="http://bugzilla.redhat.com/167944" id="167944">CAN-2005-2871 Firefox buffer overflow affects thunderbird</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168531" id="168531">CAN-2005-2701 Multiple Firefox issues (CAN-2005-2702, CAN-2005-2703, CAN-2005-2704, CAN-2005-2705, CAN-2005-2706, CAN-2005-2707)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050791002" comment="thunderbird is earlier than 0:1.0.7-1.4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050094003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050793" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:793: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:793-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-793.html" />
          <reference source="CVE" ref_id="CVE-2005-2978" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2978.html" />
    
    <description>The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps) and others.

A bug was found in the way netpbm converts Portable Anymap (PNM) files into
Portable Network Graphics (PNG). The usage of uninitialised variables in
the pnmtopng code allows an attacker to change stack contents when
converting to PNG files with pnmtopng using the '-trans' option. This may
allow an attacker to execute arbitrary code. The Common Vulnerabilities
and Exposures project assigned the name CAN-2005-2978 to this issue.

All users of netpbm should upgrade to the updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-18" />
        <updated date="2005-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2978.html">CVE-2005-2978</cve>
                <bugzilla href="http://bugzilla.redhat.com/168278" id="168278">CAN-2005-2978 Crash running pnmtopng -trans on some pnm files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793002" comment="netpbm is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793004" comment="netpbm-devel is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050793006" comment="netpbm-progs is earlier than 0:10.25-2.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050799" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:799: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:799-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-799.html" />
          <reference source="CVE" ref_id="CVE-2005-2337" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2337.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A bug was found in the way ruby handles eval statements. It is possible for
a malicious script to call eval in such a way that can allow the bypass of
certain safe-level restrictions. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-2337 to this issue.

Users of Ruby should update to these erratum packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2337.html">CVE-2005-2337</cve>
                <bugzilla href="http://bugzilla.redhat.com/169575" id="169575">CAN-2005-2337 ruby safe-level mode bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799012" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799010" comment="irb is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799014" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799008" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799004" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799002" comment="ruby is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799006" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799022" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799021" comment="irb is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543011" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799023" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543015" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799020" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543009" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799018" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543005" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799017" comment="ruby is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050799019" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050543007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050800" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:800: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:800-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-800.html" />
          <reference source="CVE" ref_id="CVE-2005-2969" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2969.html" />
          <reference source="CVE" ref_id="CVE-2005-0109" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0109.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

OpenSSL contained a software work-around for a bug in SSL handling in
Microsoft Internet Explorer version 3.0.2. This work-around is enabled in
most servers that use OpenSSL to provide support for SSL and TLS. Yutaka
Oiwa discovered that this work-around could allow an attacker, acting as a
"man in the middle" to force an SSL connection to use SSL 2.0 rather than a
stronger protocol such as SSL 3.0 or TLS 1.0. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-2969
to this issue.

A bug was also fixed in the way OpenSSL creates DSA signatures. A cache
timing attack was fixed in RHSA-2005-476 which caused OpenSSL to do private
key calculations with a fixed time window. The DSA fix for this was not
complete and the calculations are not always performed within a
fixed-window. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0109 to this issue.

Users are advised to upgrade to these updated packages, which remove the
MISE 3.0.2 work-around and contain patches to correct these issues.

Note: After installing this update, users are advised to either
restart all services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-11" />
        <updated date="2005-10-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2969.html">CVE-2005-2969</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0109.html">CVE-2005-0109</cve>
                <bugzilla href="http://bugzilla.redhat.com/169863" id="169863">CAN-2005-2969 Potential SSL 2.0 Rollback</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170036" id="170036">CAN-2005-0109 DSA signing not quite constant time</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800002" comment="openssl096b is earlier than 0:0.9.6b-16.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800004" comment="openssl is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476005" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800008" comment="openssl-perl is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476009" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800006" comment="openssl-devel is earlier than 0:0.9.7a-33.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476007" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800011" comment="openssl096b is earlier than 0:0.9.6b-22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800012" comment="openssl is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476005" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800014" comment="openssl-perl is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476009" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050800013" comment="openssl-devel is earlier than 0:0.9.7a-43.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476007" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050802" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:802: xloadimage security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:802-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-802.html" />
          <reference source="CVE" ref_id="CVE-2005-3178" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3178.html" />
    
    <description>The xloadimage utility displays images in an X Window System window, loads
images into the root window, or writes images into a file.  Xloadimage
supports many image types (including GIF, TIFF, JPEG, XPM, and XBM).

A flaw was discovered in xloadimage via which an attacker can construct a
NIFF image with a very long embedded image title. This image can cause a
buffer overflow. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-3178 to this issue.

All users of xloadimage should upgrade to this erratum package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-18" />
        <updated date="2005-10-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3178.html">CVE-2005-3178</cve>
                <bugzilla href="http://bugzilla.redhat.com/170150" id="170150">CAN-2005-3178 xloadimage NIFF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050802002" comment="xloadimage is earlier than 0:4.1-36.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050802005" comment="xloadimage is earlier than 0:4.1-36.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050332003" comment="xloadimage is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050803" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:803: lynx security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:803-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-803.html" />
          <reference source="CVE" ref_id="CVE-2005-3120" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3120.html" />
    
    <description>Lynx is a text-based Web browser. 

Ulf Härnhammar discovered a stack overflow bug in Lynx when handling
connections to NNTP (news) servers.  An attacker could create a web page
redirecting to a malicious news server which could execute arbitrary code
as the user running lynx.  The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-3120 to this issue.

Users should update to this erratum package, which contains a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2005-10-17" />
        <updated date="2007-01-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3120.html">CVE-2005-3120</cve>
                <bugzilla href="http://bugzilla.redhat.com/170253" id="170253">CAN-2005-3120 lynx buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803002" comment="lynx is earlier than 0:2.8.5-11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803005" comment="lynx is earlier than 0:2.8.5-18.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050805" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:805: pam security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:805-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-805.html" />
          <reference source="CVE" ref_id="CVE-2005-2977" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2977.html" />
    
    <description>PAM (Pluggable Authentication Modules) is a system security tool that
allows system administrators to set an authentication policy without
having to recompile programs that handle authentication.

A bug was found in the way PAM's unix_chkpwd helper program validates user
passwords when SELinux is enabled. Under normal circumstances, it is not
possible for a local non-root user to verify the password of another local
user with the unix_chkpwd command. A patch applied that adds SELinux
functionality makes it possible for a local user to use brute force
password guessing techniques against other local user accounts. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2005-2977 to
this issue.

All users of pam should upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-26" />
        <updated date="2005-10-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2977.html">CVE-2005-2977</cve>
                <bugzilla href="http://bugzilla.redhat.com/168181" id="168181">CVE-2005-2977 unix_chkpwd helper doesn't verify requesting user if SELinux is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050805004" comment="pam-devel is earlier than 0:0.77-66.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050805005" comment="pam-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050805002" comment="pam is earlier than 0:0.77-66.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050805003" comment="pam is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050807" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:807: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:807-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-807.html" />
          <reference source="CVE" ref_id="CVE-2005-3185" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3185.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols.

A stack based buffer overflow bug was found in cURL's NTLM authentication
module. It is possible to execute arbitrary code on a user's machine if
the user can be tricked into connecting to a malicious web server using
NTLM authentication. The Common Vulnerabilities and Exposures project
has assigned the name CVE-2005-3185 to this issue.

All users of curl are advised to upgrade to these updated packages, which
contain a backported patch that resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-02" />
        <updated date="2005-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3185.html">CVE-2005-3185</cve>
                <bugzilla href="http://bugzilla.redhat.com/170678" id="170678">CAN-2005-3185 NTLM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807002" comment="curl is earlier than 0:7.10.6-7.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807004" comment="curl-devel is earlier than 0:7.10.6-7.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807007" comment="curl is earlier than 0:7.12.1-6.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050807008" comment="curl-devel is earlier than 0:7.12.1-6.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050808" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:808: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:808-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-808.html" />
          <reference source="CVE" ref_id="CVE-2005-3053" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3053.html" />
          <reference source="CVE" ref_id="CVE-2005-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3108.html" />
          <reference source="CVE" ref_id="CVE-2005-3110" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3110.html" />
          <reference source="CVE" ref_id="CVE-2005-3119" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3119.html" />
          <reference source="CVE" ref_id="CVE-2005-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3180.html" />
          <reference source="CVE" ref_id="CVE-2005-3181" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3181.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

An issue was discovered that affects how page attributes are changed by the
kernel.  Video drivers, which sometimes map kernel pages with a different
caching policy than write-back, are now expected to function correctly. 
This change affects the x86, AMD64, and Intel EM64T architectures.

In addition the following security bugs were fixed:

The set_mempolicy system call did not check for negative numbers in the
policy field.  An unprivileged local user could use this flaw to cause a
denial of service (system panic).  (CVE-2005-3053)

A flaw in ioremap handling on AMD 64 and Intel EM64T systems.  An
unprivileged local user could use this flaw to cause a denial of service or
minor information leak. (CVE-2005-3108)

A race condition in the ebtables netfilter module.  On a SMP system that is
operating under a heavy load this flaw may allow remote attackers to cause
a denial of service (crash).  (CVE-2005-3110)

A memory leak was found in key handling.  An unprivileged local user could
use this flaw to cause a denial of service. (CVE-2005-3119)

A flaw in the Orinoco wireless driver.  On systems running the vulnerable
drive, a remote attacker could send carefully crafted packets which would
divulge the contents of uninitialized kernel memory.  (CVE-2005-3180)

A memory leak was found in the audit system.  An unprivileged local user
could use this flaw to cause a denial of service.  (CVE-2005-3181)

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-27" />
        <updated date="2005-12-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3053.html">CVE-2005-3053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3108.html">CVE-2005-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3110.html">CVE-2005-3110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3119.html">CVE-2005-3119</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3180.html">CVE-2005-3180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3181.html">CVE-2005-3181</cve>
                <bugzilla href="http://bugzilla.redhat.com/108616" id="108616">RHEL4 (IPF): Support for Additional function in Intel's Monticeto processor (HW)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/108827" id="108827">RHEL4:  Infiniband support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/131889" id="131889">RHEL4 U2: SATA ATAPI support (including ESB2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/139949" id="139949">sym driver creates voluminous /var/log/messages entries</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141699" id="141699">FEAT: RHEL 4 U3: ia64 needs hint@pause in spinloop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/141851" id="141851">spin loops on both ia32 and ia32e need cpu_relax</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144477" id="144477">bonding mode=6 + dhcp doesn't work correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144703" id="144703">ia32 apps that are not large file aware can access files >= 4GB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145061" id="145061">SMART support in SATA driver (P1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/149294" id="149294">qlogic fabric rediscovery functionality missing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/150893" id="150893">On few Nocona based platforms, acpi-cpufreq driver assumes the wrong CPU freq at boot time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/151549" id="151549">RHEL 4 Kernel does not provide ACL support over NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152036" id="152036">Amanda hangs on backup in case of ip_conntrack_amanda is used (RHEL4)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/153971" id="153971">large usb flash drive require reboot to mount more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/154387" id="154387">umount fails on nfs server side when nfs client does heavy io</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/155017" id="155017">Unisys' x86_64 ES7000 loses legacy devices during boot when using latest ES7000 platform code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156437" id="156437">Writing large file to 1TB ext3 volume sometimes very slow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156602" id="156602">SCTP memory consumption, additional fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156785" id="156785">Missing SHUTDOWN notification with SCTP stream socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157241" id="157241">[RHEL4-U3] PCI Hotplug - Slot powered off after enabling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/157586" id="157586">ES7000 systems won't boot with large configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/158861" id="158861">CVE-2004-1190 Continued raw access issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/159869" id="159869">Diskdump fails through ipr driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160308" id="160308">USB Key stops working after upgrade to U1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/160844" id="160844">dangling POSIX locks after close</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161362" id="161362">Oracle Hangs with directio and aio using NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161597" id="161597">sysfs_remove_dir() de-references NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161617" id="161617">RHEL4 Panics at smp_apic_timer_interrupt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161846" id="161846">Problem with b44: SIOCSIFFLAGS: Cannot allocate memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162094" id="162094">read() with count > 0xffffffff panics kernel at fs/direct-io.c:886</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162731" id="162731">[RHEL4] 'getpriority/setpriority'  broken with PRIO_USER, who=0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162732" id="162732">io_cancel doesn't work properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/162814" id="162814">Assertion failure in log_do_checkpoint</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163150" id="163150">request backport of fc transport class HBA port_id for dm-multipath</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163738" id="163738">Kernel PANIC - not syncing: fatal exception</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/163741" id="163741">qetharp 'Operation not supported' on non-layer2 guestlan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164298" id="164298">PANIC at rpc_wake_up_status</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164547" id="164547">Bug in IPv6 address adding error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165018" id="165018">Bonding driver fails to switch to backup link</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165092" id="165092">Bugs in kernel key managment syscall interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165154" id="165154">Bad order for release_region in error exit from i810_probe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165679" id="165679">CVE-2005-2458 gzip/zlib flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165741" id="165741">acct does not have Large File Support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165744" id="165744">2.6: /sbin/service iptables stop hangs on modprobe -r ipt_state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165959" id="165959">NFS/RPC - timestamp conversion is wrong</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166454" id="166454">rpmbuild --rebuild glibc-2.3.4-2.12.src.rpm hangs (same problem with glibc-2.3.4-2.9.src.rpm)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166524" id="166524">Erratic behaviour when system fd limit reached</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166589" id="166589">mount/umount can cause the block device reads to fail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166880" id="166880">[RHEL4 U1] OOPS removing ahci driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167115" id="167115">[RHEL4 U1] Bonding driver does not switch to backup interface upon active interface failure under heavy UDP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167192" id="167192">NFSv3 locking misses important kernel patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167211" id="167211">RHEL4 Panic in __wake_up_common (networking)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167630" id="167630">Multicast domain membership doesn't follow bonding failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167634" id="167634">RHEL4 __copy_user breaks on unaligned src</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167645" id="167645">RHEL4 U2 performance regression running enterprise workload</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167696" id="167696">CVE-2005-2800 SCSI proc DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167730" id="167730">FEAT RHEL4 U3: 10GigE Neterion Driver Update (S2io)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167731" id="167731">[RHEL4] hangcheck-timer not compiled in RHEL4 on IA64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/167907" id="167907">SCTP association restart problem, possible backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168090" id="168090">ipmi_poweroff driver update for Dell &lt;8G servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168262" id="168262">[RHEL4 U1][diskdump] Diskdump from OS_INIT fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168431" id="168431">autofs removes leading path components of /net mounts on timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168483" id="168483">FEAT: [RHEL4 U3] kernel dm: Statistic information about dm devices (*)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168659" id="168659">CVE-2005-3044 lost fput and sockfd_put could lead to DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168775" id="168775">wait() and waitpid() return inconsistencies under high load</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168777" id="168777">CVE-2005-3276 sys_get_thread_area minor info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168824" id="168824">[FEAT:][RHEL 4 U3]LVM2 Snapshot support of root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/168924" id="168924">CVE-2005-2709 More sysctl flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169042" id="169042">[Texas Instruments] nfs bindresvport: Address already in use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169130" id="169130">CVE-2005-3356 double decrement of mqueue_mnt->mnt_count in sys_mq_open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169149" id="169149">oops in gss_pipe_release()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169184" id="169184">ls hangs on krb5 mountd when user has not kinit-ed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169197" id="169197">NFS client oops when debugging is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170146" id="170146">CRM648268: kernel reporting init process cutime as very large negative value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170262" id="170262">CVE-2005-3106 exec_mmap race DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170423" id="170423">Cache invalidation bug in nfs v3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170487" id="170487">Bad: kernel panic on boot (kernel-2.6.9-22.EL)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170546" id="170546">kernel_lock() problem through NFS mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170656" id="170656">iSCSI connection recovery uses session address instead of portal address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170864" id="170864">device-mapper mirroring backwards compatibility issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/170887" id="170887">Neterion(S2io) adapter not functional after running offline diagnostics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171002" id="171002">CVE-2005-3109 HFS oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171112" id="171112">Kernel oops killing process with open files on a NFS3 krb5 mount after /var/lib/nfs/rpc_pipefs has been unmounted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171141" id="171141">FEAT RHEL4 U3 [diskdump]: kernel - support compressing dump data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171220" id="171220">USB: khubd deadlock on error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171705" id="171705">Kernel key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171715" id="171715">nfsd: clear signals before exiting the nfsd() thread</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171765" id="171765">linux-2.6.13-key-reiserfs.patch is incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171950" id="171950">Can't reboot on IBM xSeries 236.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171989" id="171989">rhel4 modules loading signing issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172081" id="172081">rename(2) onto an empty directory fails on NFS file systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172214" id="172214">Large LUNS can't be seen with Hitachi Open-L SAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172487" id="172487">Difficulty with some iSCSI targets in iscsi_sfnet</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172595" id="172595">netpoll can dereference a null pointer, causing a system crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172598" id="172598">[RHEL4] tuxstat SIGSEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172892" id="172892">kernel dm: dm-ioctl memory leak on attempt to load non-existing mapping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172986" id="172986">autofs doesn't remount if nfs server is unreachable at expire time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173155" id="173155">kernel dm: DM_LIST_VERSIONS_CMD ioctl reponse truncated</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173156" id="173156">kernel dm: Notify userspace when a device is renamed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173157" id="173157">kernel dm-log: big endian 64-bit corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173158" id="173158">kernel dm-log: Make mirror log arch-independent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173159" id="173159">kernel dm: move bdget outside lockfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173161" id="173161">kernel dm: Make lock_fs optional.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173163" id="173163">kernel dm snapshot: Separate out metadata reading.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173164" id="173164">kernel dm snapshot: Load metadata on table creation not resumption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173166" id="173166">kernel dm snapshot: Reduce PF_MEMALLOC usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173174" id="173174">kernel dm multipath: Fix do_end_io locking.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173194" id="173194">race condition when expiring ghosted autofs mounts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173206" id="173206">kernel dm snapshot: bio_list_merge fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173304" id="173304">Fix for SystemTap bugzilla #1345 - return probe on do_execve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173354" id="173354">unable to create sgi_sn/ptc_statistics" printed to the console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173486" id="173486">Further key management facility improvements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173493" id="173493">Permit key management to request already running process to instantiate a key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173981" id="173981">kernel bug at mm/prio_tree.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808002" comment="kernel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808006" comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808004" comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808010" comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092011" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808012" comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808014" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050092015" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050808008" comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050809" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:809: ethereal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:809-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-809.html" />
          <reference source="CVE" ref_id="CVE-2005-3241" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3241.html" />
          <reference source="CVE" ref_id="CVE-2005-3242" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3242.html" />
          <reference source="CVE" ref_id="CVE-2005-3243" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3243.html" />
          <reference source="CVE" ref_id="CVE-2005-3244" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3244.html" />
          <reference source="CVE" ref_id="CVE-2005-3245" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3245.html" />
          <reference source="CVE" ref_id="CVE-2005-3246" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3246.html" />
          <reference source="CVE" ref_id="CVE-2005-3247" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3247.html" />
          <reference source="CVE" ref_id="CVE-2005-3248" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3248.html" />
          <reference source="CVE" ref_id="CVE-2005-3249" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3249.html" />
          <reference source="CVE" ref_id="CVE-2005-3184" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3184.html" />
    
    <description>The ethereal package is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws and cause Ethereal to crash or potentially execute
arbitrary code. The Common Vulnerabilities and Exposures project
has assigned the names CVE-2005-3241, CVE-2005-3242, CVE-2005-3243,
CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248,
CVE-2005-3249, and CVE-2005-3184 to these issues.

Users of ethereal should upgrade to these updated packages, which contain
version 0.10.13 and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-10-25" />
        <updated date="2005-10-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3241.html">CVE-2005-3241</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3242.html">CVE-2005-3242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3243.html">CVE-2005-3243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3244.html">CVE-2005-3244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3245.html">CVE-2005-3245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3246.html">CVE-2005-3246</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3247.html">CVE-2005-3247</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3248.html">CVE-2005-3248</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3249.html">CVE-2005-3249</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3184.html">CVE-2005-3184</cve>
                <bugzilla href="http://bugzilla.redhat.com/171062" id="171062">CVE-2005-3241 Multiple ethereal issues (CVE-2005-3242 CVE-2005-3243 CVE-2005-3244 CVE-2005-3245 CVE-2005-3246 CVE-2005-3247 CVE-2005-3248 CVE-2005-3249 CVE-2005-3184)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809004" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809002" comment="ethereal is earlier than 0:0.10.13-1.EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809008" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050809007" comment="ethereal is earlier than 0:0.10.13-1.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050810" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:810: gdk-pixbuf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:810-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-810.html" />
          <reference source="CVE" ref_id="CVE-2005-3186" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3186.html" />
          <reference source="CVE" ref_id="CVE-2005-2976" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2976.html" />
          <reference source="CVE" ref_id="CVE-2005-2975" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2975.html" />
    
    <description>The gdk-pixbuf package contains an image loading library used with the
GNOME GUI desktop environment.

A bug was found in the way gdk-pixbuf processes XPM images. An attacker
could create a carefully crafted XPM file in such a way that it could cause
an application linked with gdk-pixbuf to execute arbitrary code when the
file was opened by a victim. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an integer overflow bug in the way gdk-pixbuf
processes XPM images. An attacker could create a carefully crafted XPM file
in such a way that it could cause an application linked with gdk-pixbuf to
execute arbitrary code or crash when the file was opened by a victim. The
Common Vulnerabilities and Exposures project has assigned the name
CVE-2005-2976 to this issue.

Ludwig Nussel also discovered an infinite-loop denial of service bug in the
way gdk-pixbuf processes XPM images. An attacker could create a carefully
crafted XPM file in such a way that it could cause an application linked
with gdk-pixbuf to stop responding when the file was opened by a victim.
The Common Vulnerabilities and Exposures project has assigned the name
CVE-2005-2975 to this issue.

Users of gdk-pixbuf are advised to upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-15" />
        <updated date="2005-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3186.html">CVE-2005-3186</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2976.html">CVE-2005-2976</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2975.html">CVE-2005-2975</cve>
                <bugzilla href="http://bugzilla.redhat.com/171071" id="171071">CVE-2005-3186 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171900" id="171900">CVE-2005-2975 Multiple XPM processing issues (CVE-2005-2976)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810006" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343007" comment="gdk-pixbuf-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810004" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810002" comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810010" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343005" comment="gdk-pixbuf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050810009" comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050343003" comment="gdk-pixbuf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050811" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:811: gtk2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:811-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-811.html" />
          <reference source="CVE" ref_id="CVE-2005-3186" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3186.html" />
          <reference source="CVE" ref_id="CVE-2005-2975" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2975.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System.

A bug was found in the way gtk2 processes XPM images. An attacker could
create a carefully crafted XPM file in such a way that it could cause an
application linked with gtk2 to execute arbitrary code when the file was
opened by a victim. The Common Vulnerabilities and Exposures project has
assigned the name CVE-2005-3186 to this issue.

Ludwig Nussel discovered an infinite-loop denial of service bug in the way
gtk2 processes XPM images. An attacker could create a carefully crafted XPM
file in such a way that it could cause an application linked with gtk2 to
stop responding when the file was opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2005-2975
to this issue.

Users of gtk2 are advised to upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-15" />
        <updated date="2005-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3186.html">CVE-2005-3186</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2975.html">CVE-2005-2975</cve>
                <bugzilla href="http://bugzilla.redhat.com/171073" id="171073">CVE-2005-3186 XPM buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171904" id="171904">CVE-2005-2975 gtk2 XPM DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811002" comment="gtk2 is earlier than 0:2.2.4-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811004" comment="gtk2-devel is earlier than 0:2.2.4-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811007" comment="gtk2 is earlier than 0:2.4.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050811008" comment="gtk2-devel is earlier than 0:2.4.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050344005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050812" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:812: wget security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:812-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-812.html" />
          <reference source="CVE" ref_id="CVE-2005-3185" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3185.html" />
    
    <description>GNU Wget is a file retrieval utility that can use either the HTTP or
FTP protocols.

A stack based buffer overflow bug was found in the wget implementation of
NTLM authentication.  An attacker could execute arbitrary code on a user's
machine if the user can be tricked into connecting to a malicious web
server using NTLM authentication. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-3185 to this issue.

All users of wget are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-03" />
        <updated date="2005-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3185.html">CVE-2005-3185</cve>
                <bugzilla href="http://bugzilla.redhat.com/170666" id="170666">CVE-2005-3185 NTLM buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050812002" comment="wget is earlier than 0:1.10.2-0.30E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050812005" comment="wget is earlier than 0:1.10.2-0.40E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050771003" comment="wget is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050825" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:825: lm_sensors security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:825-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-825.html" />
          <reference source="CVE" ref_id="CVE-2005-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2672.html" />
    
    <description>The lm_sensors package includes a collection of modules for general SMBus
access and hardware monitoring. This package requires special support which
is not in standard version 2.2 kernels.

A bug was found in the way the pwmconfig tool creates temporary files. It
is possible that a local attacker could leverage this flaw to overwrite
arbitrary files located on the system. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-2672 to this issue.

Users of lm_sensors are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-10" />
        <updated date="2005-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2672.html">CVE-2005-2672</cve>
                <bugzilla href="http://bugzilla.redhat.com/166672" id="166672">CVE-2005-2672 lm_sensors pwmconfig insecure temporary file usage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050825004" comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050825005" comment="lm_sensors-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050825002" comment="lm_sensors is earlier than 0:2.8.7-2.40.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050825003" comment="lm_sensors is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050828" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:828: libungif security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:828-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-828.html" />
          <reference source="CVE" ref_id="CVE-2005-2974" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2974.html" />
          <reference source="CVE" ref_id="CVE-2005-3350" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3350.html" />
    
    <description>The libungif package contains a shared library of functions for loading and
saving GIF format image files.

Several bugs in the way libungif decodes GIF images were discovered. An
attacker could create a carefully crafted GIF image file in such a way that
it could cause an application linked with libungif to crash or execute
arbitrary code when the file is opened by a victim. The Common
Vulnerabilities and Exposures project has assigned the names CVE-2005-2974
and CVE-2005-3350 to these issues.

All users of libungif are advised to upgrade to these updated packages,
which contain backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-03" />
        <updated date="2005-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2974.html">CVE-2005-2974</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3350.html">CVE-2005-3350</cve>
                <bugzilla href="http://bugzilla.redhat.com/171413" id="171413">CVE-2005-2974 Several libungif issues (CVE-2005-3350)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828002" comment="libungif is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828003" comment="libungif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828006" comment="libungif-progs is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828007" comment="libungif-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828004" comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828005" comment="libungif-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828009" comment="libungif is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828003" comment="libungif is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828011" comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828007" comment="libungif-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050828010" comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050828005" comment="libungif-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050830" version="501" class="patch">
      <metadata>
        <title>RHSA-2005:830: openssl096b security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:830-00" ref_url="https://rhn.redhat.com/errata/RHSA-2005-830.html" />
          <reference source="CVE" ref_id="CVE-2004-0079" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0079.html" />
    
    <description>The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),
Transport Layer Security (TLS v1) protocols, and serves as a full-strength
general purpose cryptography library. OpenSSL 0.9.6b libraries are provided
for Red Hat Enterprise Linux 3 and 4 to allow compatibility with legacy
applications.

Testing performed by the OpenSSL group using the Codenomicon TLS Test Tool
uncovered a null-pointer assignment in the do_change_cipher_spec()
function.  A remote attacker could perform a carefully crafted SSL/TLS
handshake against a server that uses the OpenSSL library in such a way as
to cause OpenSSL to crash.  Depending on the server this could lead to a
denial of service.  (CVE-2004-0079)

This issue was reported as not affecting OpenSSL versions prior to 0.9.6c,
and testing with the Codenomicon Test Tool showed that OpenSSL 0.9.6b as
shipped as a compatibility library with Red Hat Enterprise Linux 3 and 4
did not crash.  However, an alternative reproducer has been written which
shows that this issue does affect versions of OpenSSL prior to 0.9.6c.

Note that Red Hat does not ship any applications with Red Hat Enterprise
Linux 3 or 4 that use these compatibility libraries.  

Users of the OpenSSL096b compatibility package are advised to upgrade to
these updated packages, which contain a patch provided by the OpenSSL group
that protect against this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-02" />
        <updated date="2005-11-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0079.html">CVE-2004-0079</cve>
                <bugzilla href="http://bugzilla.redhat.com/172094" id="172094">CVE-2004-0079 OpenSSL remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050830002" comment="openssl096b is earlier than 0:0.9.6b-16.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050830005" comment="openssl096b is earlier than 0:0.9.6b-22.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050476003" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050831" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:831: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:831-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-831.html" />
          <reference source="CVE" ref_id="CVE-2005-3353" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3353.html" />
          <reference source="CVE" ref_id="CVE-2005-3388" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3388.html" />
          <reference source="CVE" ref_id="CVE-2005-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3389.html" />
          <reference source="CVE" ref_id="CVE-2005-3390" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3390.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A flaw was found in the way PHP registers global variables during a file
upload request.  A remote attacker could submit a carefully crafted
multipart/form-data POST request that would overwrite the $GLOBALS array,
altering expected script behavior, and possibly leading to the execution of
arbitrary PHP commands.  Please note that this vulnerability only affects
installations which have register_globals enabled in the PHP configuration
file, which is not a default or recommended option.  The Common
Vulnerabilities and Exposures project assigned the name CVE-2005-3390 to
this issue.

A flaw was found in the PHP parse_str() function. If a PHP script passes
only one argument to the parse_str() function, and the script can be forced
to abort execution during operation (for example due to the memory_limit
setting), the register_globals may be enabled even if it is disabled in the
PHP configuration file.  This vulnerability only affects installations that
have PHP scripts using the parse_str function in this way.  (CVE-2005-3389)

A Cross-Site Scripting flaw was found in the phpinfo() function. If a
victim can be tricked into following a malicious URL to a site with a page
displaying the phpinfo() output, it may be possible to inject javascript
or HTML content into the displayed page or steal data such as cookies. 
This vulnerability only affects installations which allow users to view the
output of the phpinfo() function.  As the phpinfo() function outputs a
large amount of information about the current state of PHP, it should only
be used during debugging or if protected by authentication.  (CVE-2005-3388)

A denial of service flaw was found in the way PHP processes EXIF image
data.  It is possible for an attacker to cause PHP to crash by supplying
carefully crafted EXIF image data. (CVE-2005-3353)

Users of PHP should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-10" />
        <updated date="2005-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3353.html">CVE-2005-3353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3388.html">CVE-2005-3388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3389.html">CVE-2005-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3390.html">CVE-2005-3390</cve>
                <bugzilla href="http://bugzilla.redhat.com/172207" id="172207">CVE-2005-3390 PHP register globals arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172209" id="172209">CVE-2005-3389 PHP parse_str can enable register_globals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172212" id="172212">CVE-2005-3388 PHP phpinfo() XSS attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172589" id="172589">CVE-2005-3353 PHP exif data DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831014" comment="php-odbc is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831010" comment="php-mysql is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831002" comment="php is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831012" comment="php-pgsql is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831004" comment="php-devel is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831006" comment="php-imap is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831008" comment="php-ldap is earlier than 0:4.3.2-26.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831036" comment="php-gd is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831025" comment="php-odbc is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831023" comment="php-mysql is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831017" comment="php is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831030" comment="php-xmlrpc is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831032" comment="php-mbstring is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831024" comment="php-pgsql is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831018" comment="php-devel is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831034" comment="php-ncurses is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831026" comment="php-snmp is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831021" comment="php-imap is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831019" comment="php-pear is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831028" comment="php-domxml is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050831022" comment="php-ldap is earlier than 0:4.3.9-3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050839" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:839: lynx security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-839.html" />
          <reference source="CVE" ref_id="CVE-2005-2929" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2929.html" />
    
    <description>Lynx is a text-based Web browser.

An arbitrary command execute bug was found in the lynx "lynxcgi:" URI
handler. An attacker could create a web page redirecting to a malicious URL
which could execute arbitrary code as the user running lynx. The Common
Vulnerabilities and Exposures project assigned the name CVE-2005-2929 to
this issue.

Users should update to this erratum package, which contains a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-11-11" />
        <updated date="2005-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2929.html">CVE-2005-2929</cve>
                <bugzilla href="http://bugzilla.redhat.com/172972" id="172972">CVE-2005-2929 lynx arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050839002" comment="lynx is earlier than 0:2.8.5-11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050839005" comment="lynx is earlier than 0:2.8.5-18.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050803003" comment="lynx is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050840" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:840: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:840-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-840.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.

Several flaws were discovered in Xpdf.  An attacker could construct a
carefully crafted PDF file that could cause Xpdf to crash or possibly
execute arbitrary code when opened.  The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of Xpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.

Red Hat would like to thank Derek B. Noonburg for reporting this issue and
providing a patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/173888" id="173888">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050840002" comment="xpdf is earlier than 1:2.02-9.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050840005" comment="xpdf is earlier than 1:3.00-11.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050843" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:843: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:843-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-843.html" />
          <reference source="CVE" ref_id="CVE-2005-3632" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3632.html" />
          <reference source="CVE" ref_id="CVE-2005-3662" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3662.html" />
    
    <description>The netpbm package contains a library of functions that support programs
for handling various graphics file formats.

A stack based buffer overflow bug was found in the way netpbm converts
Portable Anymap (PNM) files into Portable Network Graphics (PNG). A
specially crafted PNM file could allow an attacker to execute arbitrary
code by attempting to convert a PNM file to a PNG file when using pnmtopng
with the '-text' option. The Common Vulnerabilities and Exposures project
has assigned the name CVE-2005-3632 to this issue.

An "off by one" bug was found in the way netpbm converts Portable Anymap
(PNM) files into Portable Network Graphics (PNG). If a victim attempts to
convert a specially crafted 256 color PNM file to a PNG file, then it can
cause the pnmtopng utility to crash. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-3662 to this issue.

All users of netpbm should upgrade to these updated packages, which contain
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3632.html">CVE-2005-3632</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3662.html">CVE-2005-3662</cve>
                <bugzilla href="http://bugzilla.redhat.com/173342" id="173342">CVE-2005-3662 netpbm off by one error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173344" id="173344">CVE-2005-3632 Netpbm buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843002" comment="netpbm is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843004" comment="netpbm-devel is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050843006" comment="netpbm-progs is earlier than 0:9.24-11.30.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050743007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050848" version="503" class="patch">
      <metadata>
        <title>RHSA-2005:848: libc-client security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:848-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-848.html" />
          <reference source="CVE" ref_id="CVE-2005-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2933.html" />
    
    <description>C-client is a common API for accessing mailboxes.

A buffer overflow flaw was discovered in the way C-client parses user
supplied mailboxes. If an authenticated user requests a specially crafted
mailbox name, it may be possible to execute arbitrary code on a server that
uses C-client to access mailboxes. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-2933 to this issue.

All users of libc-client should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2933.html">CVE-2005-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/171344" id="171344">CVE-2005-2933 imap buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050848002" comment="libc-client is earlier than 0:2002e-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050848003" comment="libc-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050848004" comment="libc-client-devel is earlier than 0:2002e-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050848005" comment="libc-client-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050850" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:850: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:850-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-850.html" />
          <reference source="CVE" ref_id="CVE-2005-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2933.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access protocols.

A buffer overflow flaw was discovered in the way the c-client library
parses user supplied mailboxes. If an authenticated user requests a
specially crafted mailbox name, it may be possible to execute arbitrary
code on a server that uses the library. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2005-2933 to this issue.

All users of imap should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-06" />
        <updated date="2005-12-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2933.html">CVE-2005-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/169953" id="169953">CVE-2005-2933 imap buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850006" comment="imap-utils is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850004" comment="imap-devel is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050850002" comment="imap is earlier than 1:2002d-12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050128003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050864" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:864: udev security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:864-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-864.html" />
          <reference source="CVE" ref_id="CVE-2005-3631" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3631.html" />
    
    <description>The udev package contains an implementation of devfs in userspace using
sysfs and /sbin/hotplug.

Richard Cunningham discovered a flaw in the way udev sets permissions on
various files in /dev/input. It may be possible for an authenticated
attacker to gather sensitive data entered by a user at the console, such as
passwords. The Common Vulnerabilities and Exposures project has assigned
the name CVE-2005-3631 to this issue.

All users of udev should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3631.html">CVE-2005-3631</cve>
                <bugzilla href="http://bugzilla.redhat.com/174845" id="174845">CVE-2005-3631 /dev/input/* incorrect permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050864002" comment="udev is earlier than 0:039-10.10.EL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050864003" comment="udev is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050867" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:867: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:867-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-867.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The gpdf package is a GNOME based viewer for Portable Document Format
(PDF) files.

Several flaws were discovered in gpdf. An attacker could construct a
carefully crafted PDF file that could cause gpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of gpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175100" id="175100">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050867002" comment="gpdf is earlier than 0:2.8.2-7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050868" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:868: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:868-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-868.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3624" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3624.html" />
          <reference source="CVE" ref_id="CVE-2005-3625" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3625.html" />
          <reference source="CVE" ref_id="CVE-2005-3626" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3626.html" />
          <reference source="CVE" ref_id="CVE-2005-3627" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3627.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer.

Several flaws were discovered in kpdf. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.

Users of kpdf should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3624.html">CVE-2005-3624</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3625.html">CVE-2005-3625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3626.html">CVE-2005-3626</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3627.html">CVE-2005-3627</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175105" id="175105">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050868002" comment="kdegraphics is earlier than 7:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050868004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050875" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:875: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:875-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-875.html" />
          <reference source="CVE" ref_id="CVE-2005-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4077.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols.

Stefan Esser discovered an off-by-one bug in curl. It may be possible to
execute arbitrary code on a user's machine if the user can be tricked into
executing curl with a carefully crafted URL. The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-4077 to this issue. 

All users of curl are advised to upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4077.html">CVE-2005-4077</cve>
                <bugzilla href="http://bugzilla.redhat.com/175266" id="175266">CVE-2005-4077 SA17907 cURL/libcURL URL Parsing Off-By-One Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050875002" comment="curl is earlier than 0:7.12.1-8.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340003" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050875004" comment="curl-devel is earlier than 0:7.12.1-8.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050340005" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050878" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:878: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:878-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-878.html" />
          <reference source="CVE" ref_id="CVE-2005-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3191.html" />
          <reference source="CVE" ref_id="CVE-2005-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3192.html" />
          <reference source="CVE" ref_id="CVE-2005-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3193.html" />
          <reference source="CVE" ref_id="CVE-2005-3628" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3628.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Several flaws were discovered in the way CUPS processes PDF files. An
attacker could construct a carefully crafted PDF file that could cause CUPS
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project assigned the names CVE-2005-3191,
CVE-2005-3192, and CVE-2005-3193 to these issues.

All users of CUPS should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3191.html">CVE-2005-3191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3192.html">CVE-2005-3192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3193.html">CVE-2005-3193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3628.html">CVE-2005-3628</cve>
                <bugzilla href="http://bugzilla.redhat.com/175645" id="175645">CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878004" comment="cups-devel is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878006" comment="cups-libs is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878002" comment="cups is earlier than 1:1.1.17-13.3.34" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050878009" comment="cups is earlier than 1:1.1.22-0.rc1.9.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050880" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:880: perl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:880-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-880.html" />
          <reference source="CVE" ref_id="CVE-2005-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3962.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

An integer overflow bug was found in Perl's format string processor.  It is
possible for an attacker to cause perl to crash or execute arbitrary code
if the attacker is able to process a malicious format string.  This issue
is only exploitable through a script which passes arbitrary untrusted
strings to the format string processor.  The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-3962 to this issue.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues as well as fixes for
several bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3962.html">CVE-2005-3962</cve>
                <bugzilla href="http://bugzilla.redhat.com/170088" id="170088">bits/resource.ph has syntax errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171111" id="171111">(libperl) could not run system-config-printer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172327" id="172327">getgrnam() crashes with "Out of memory" if /etc/group contains   long lines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174683" id="174683">CVE-2005-3962 Perl integer overflow issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175104" id="175104">MakeMaker::MM_Unix doesn't honor LD_RUN_PATH requirements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175129" id="175129">missing C standard headers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050880004" comment="perl-suidperl is earlier than 3:5.8.5-24.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050880002" comment="perl is earlier than 3:5.8.5-24.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050881" version="502" class="patch">
      <metadata>
        <title>RHSA-2005:881: perl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2005:881-01" ref_url="https://rhn.redhat.com/errata/RHSA-2005-881.html" />
          <reference source="CVE" ref_id="CVE-2004-0976" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0976.html" />
          <reference source="CVE" ref_id="CVE-2005-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0448.html" />
          <reference source="CVE" ref_id="CVE-2005-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3962.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

An integer overflow bug was found in Perl's format string processor.  It is
possible for an attacker to cause perl to crash or execute arbitrary code
if the attacker is able to process a malicious format string.  This issue
is only exploitable through a script wich passes arbitrary untrusted
strings to the format string processor.  The Common Vulnerabilities and
Exposures project assigned the name CVE-2005-3962 to this issue.

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module
removed directory trees.  If a local user has write permissions to a
subdirectory within the tree being removed by File::Path::rmtree, it is
possible for them to create setuid binary files.  (CVE-2005-0448)

Solar Designer discovered several temporary file bugs in various Perl
modules.  A local attacker could overwrite or create files as the user
running a Perl script that uses a vulnerable module.  (CVE-2004-0976)

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues as well as fixes for
several bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-12-20" />
        <updated date="2005-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0976.html">CVE-2004-0976</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0448.html">CVE-2005-0448</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3962.html">CVE-2005-3962</cve>
                <bugzilla href="http://bugzilla.redhat.com/123176" id="123176">[RFE] Need new perl rpm release that fixes threaded memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/135975" id="135975">Perl's 'study' function breaks regexp matching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/136325" id="136325">CVE-2004-0976 temporary file vulnerabilities in Perl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137075" id="137075">Apparent utf8 bug in Perl's join()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/145215" id="145215">garbage after split()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/147946" id="147946">Man::Pod does not return true</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161053" id="161053">CVE-2005-0448 perl File::Path.pm rmtree race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/165078" id="165078">Broken POSIX in perl-5.8.0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166732" id="166732">'split'/'index' problem for utf8</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172160" id="172160">perl bug # 22372: SIGSEGV in sv_chop()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172256" id="172256">bits/resource.ph has syntax errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172317" id="172317">(libperl) could not run system-config-printer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/174717" id="174717">CVE-2005-3962 Perl integer overflow issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175135" id="175135">Cannot set undef timeout in perl 5.8.0 IO::Socket</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050009001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881006" comment="perl-CGI is earlier than 2:2.89-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105007" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881008" comment="perl-DB_File is earlier than 2:1.806-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105009" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881010" comment="perl-suidperl is earlier than 2:5.8.0-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103005" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881004" comment="perl-CPAN is earlier than 2:1.61-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050105005" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20050881002" comment="perl is earlier than 2:5.8.0-90.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20050103003" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
</definitions>

<tests>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009001" version="502" comment="Red Hat Enterprise Linux 3 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009002" version="502" comment="kdelibs is earlier than 6:3.1.3-6.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009003" version="502" comment="kdelibs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009004" version="502" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009005" version="502" comment="kdelibs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009006" version="502" comment="kdebase is earlier than 6:3.1.3-5.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009007" version="502" comment="kdebase is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009008" version="502" comment="kdebase-devel is earlier than 6:3.1.3-5.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050009009" version="502" comment="kdebase-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010002" version="502" comment="vim is earlier than 1:6.3.046-0.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050010003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010003" version="502" comment="vim is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010004" version="502" comment="vim-common is earlier than 1:6.3.046-0.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050010003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010005" version="502" comment="vim-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010006" version="502" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050010003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010007" version="502" comment="vim-minimal is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010008" version="502" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050010003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010009" version="502" comment="vim-enhanced is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010010" version="502" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050010003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050010011" version="502" comment="vim-X11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050011002" version="502" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050011003" version="502" comment="ethereal is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050011004" version="502" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050011005" version="502" comment="ethereal-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012002" version="502" comment="krb5 is earlier than 0:1.2.7-38" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050012003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012003" version="502" comment="krb5 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012004" version="502" comment="krb5-devel is earlier than 0:1.2.7-38" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050012003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012005" version="502" comment="krb5-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012006" version="502" comment="krb5-libs is earlier than 0:1.2.7-38" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050012003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012007" version="502" comment="krb5-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012008" version="502" comment="krb5-server is earlier than 0:1.2.7-38" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050012003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012009" version="502" comment="krb5-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012010" version="502" comment="krb5-workstation is earlier than 0:1.2.7-38" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050012003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050012011" version="502" comment="krb5-workstation is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013002" version="502" comment="cups is earlier than 1:1.1.17-13.3.22" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013003" version="502" comment="cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.22" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013005" version="502" comment="cups-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.22" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050013007" version="502" comment="cups-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050018002" version="502" comment="xpdf is earlier than 1:2.02-9.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050018003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050018003" version="502" comment="xpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050019002" version="502" comment="libtiff is earlier than 0:3.5.7-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050019003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050019003" version="502" comment="libtiff is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050019004" version="502" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050019003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050019005" version="502" comment="libtiff-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050021002" version="502" comment="kdegraphics is earlier than 7:3.1.3-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050021003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050021003" version="502" comment="kdegraphics is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050021004" version="502" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050021003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050021005" version="502" comment="kdegraphics-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025001" version="502" comment="Red Hat Enterprise Linux 4 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050025002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025002" version="502" comment="exim is earlier than 0:4.43-1.RHEL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050025003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025003" version="502" comment="exim is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025004" version="502" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050025003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025005" version="502" comment="exim-mon is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025006" version="502" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050025003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025007" version="502" comment="exim-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025008" version="502" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050025003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050025009" version="502" comment="exim-sa is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026002" version="502" comment="tetex is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026003" version="502" comment="tetex is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026004" version="502" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026005" version="502" comment="tetex-latex is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026006" version="502" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026007" version="502" comment="tetex-xdvi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026008" version="502" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026009" version="502" comment="tetex-dvips is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026010" version="502" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026011" version="502" comment="tetex-afm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026012" version="502" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026013" version="502" comment="tetex-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026014" version="502" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050026003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050026015" version="502" comment="tetex-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032002" version="502" comment="php is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032003" version="502" comment="php is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032004" version="502" comment="php-devel is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032005" version="502" comment="php-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032006" version="502" comment="php-pear is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032007" version="502" comment="php-pear is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032008" version="502" comment="php-imap is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032009" version="502" comment="php-imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032010" version="502" comment="php-ldap is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032011" version="502" comment="php-ldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032012" version="502" comment="php-mysql is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032013" version="502" comment="php-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032014" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032015" version="502" comment="php-pgsql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032016" version="502" comment="php-odbc is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032017" version="502" comment="php-odbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032018" version="502" comment="php-snmp is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032019" version="502" comment="php-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032020" version="502" comment="php-domxml is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032021" version="502" comment="php-domxml is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032022" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032023" version="502" comment="php-xmlrpc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032024" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032025" version="502" comment="php-mbstring is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032026" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032027" version="502" comment="php-ncurses is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032028" version="502" comment="php-gd is earlier than 0:4.3.9-3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050032003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050032029" version="502" comment="php-gd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050033002" version="502" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050033002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050033003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050033003" version="502" comment="alsa-lib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050033002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050033004" version="502" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050033003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050033003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050033005" version="502" comment="alsa-lib-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050033003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050034002" version="502" comment="xpdf is earlier than 1:3.00-11.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050034003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050035002" version="502" comment="libtiff is earlier than 0:3.6.1-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050035003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050035004" version="502" comment="libtiff-devel is earlier than 0:3.6.1-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050019003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050035003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050036002" version="502" comment="vim is earlier than 1:6.3.046-0.40E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050036004" version="502" comment="vim-common is earlier than 1:6.3.046-0.40E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050036006" version="502" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050036008" version="502" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050036010" version="502" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050037002" version="502" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050037003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050037004" version="502" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050037003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038002" version="504" comment="mozilla is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038003" version="504" comment="mozilla is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038004" version="504" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038005" version="504" comment="mozilla-nspr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038006" version="504" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038007" version="504" comment="mozilla-nspr-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038008" version="504" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038009" version="504" comment="mozilla-nss is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038010" version="504" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038011" version="504" comment="mozilla-nss-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038012" version="504" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038013" version="504" comment="mozilla-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038014" version="504" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038015" version="504" comment="mozilla-mail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038016" version="504" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038017" version="504" comment="mozilla-chat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038018" version="504" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038019" version="504" comment="mozilla-js-debugger is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038020" version="504" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050038003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050038021" version="504" comment="mozilla-dom-inspector is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050039002" version="502" comment="enscript is earlier than 0:1.6.1-24.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050039002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050039003" version="502" comment="enscript is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050039002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050040002" version="502" comment="enscript is earlier than 0:1.6.1-28.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050039002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050040003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043002" version="502" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043003" version="502" comment="kernel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043004" version="502" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043005" version="502" comment="kernel-source is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043006" version="502" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043007" version="502" comment="kernel-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043008" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043009" version="502" comment="kernel-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043010" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043011" version="502" comment="kernel-smp-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043012" version="502" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043013" version="502" comment="kernel-smp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043014" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043015" version="502" comment="kernel-BOOT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043016" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043017" version="502" comment="kernel-hugemem-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043018" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050043003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050043019" version="502" comment="kernel-hugemem is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050045002" version="502" comment="krb5 is earlier than 0:1.3.4-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050045004" version="502" comment="krb5-devel is earlier than 0:1.3.4-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050045006" version="502" comment="krb5-libs is earlier than 0:1.3.4-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050045008" version="502" comment="krb5-server is earlier than 0:1.3.4-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050045010" version="502" comment="krb5-workstation is earlier than 0:1.3.4-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050049002" version="502" comment="cups is earlier than 1:1.1.17-13.3.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050049003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050049004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050049003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050049006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050049003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050053002" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050053003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050053004" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050053003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050053006" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050053003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050057002" version="502" comment="gpdf is earlier than 0:2.8.2-4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050057002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050057003" version="502" comment="gpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050057002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050059002" version="502" comment="xpdf is earlier than 1:2.02-9.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050059003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050060002" version="502" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050060003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050060003" version="502" comment="squid is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050061002" version="502" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050065002" version="502" comment="kdelibs is earlier than 6:3.3.1-3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050065003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050065004" version="502" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050065003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050066002" version="502" comment="kdegraphics is earlier than 7:3.3.1-3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050066003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050066004" version="502" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050066003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050068002" version="502" comment="less is earlier than 0:378-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050068002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050068003" version="502" comment="less is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050068002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050069002" version="502" comment="perl-DBI is earlier than 0:1.32-9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050069002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050069003" version="502" comment="perl-DBI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050069002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070002" version="502" comment="ImageMagick is earlier than 0:5.5.6-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050070003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070003" version="502" comment="ImageMagick is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070004" version="502" comment="ImageMagick-devel is earlier than 0:5.5.6-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050070003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070005" version="502" comment="ImageMagick-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070006" version="502" comment="ImageMagick-perl is earlier than 0:5.5.6-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050070003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070007" version="502" comment="ImageMagick-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070008" version="502" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050070003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070009" version="502" comment="ImageMagick-c++ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070010" version="502" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050070003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050070011" version="502" comment="ImageMagick-c++-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050071002" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050071003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050071004" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050071003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050071006" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050071003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050071008" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050071003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050071010" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050071003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050072002" version="502" comment="perl-DBI is earlier than 0:1.40-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050069002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050072003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050073002" version="502" comment="cpio is earlier than 0:2.5-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050073002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050073003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050073003" version="502" comment="cpio is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050073002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050074002" version="502" comment="rsh is earlier than 0:0.17-17.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050074003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050074003" version="502" comment="rsh is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050074004" version="502" comment="rsh-server is earlier than 0:0.17-17.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050074003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050074005" version="502" comment="rsh-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050080002" version="502" comment="cpio is earlier than 0:2.5-3e.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050073002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050080003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081002" version="503" comment="ghostscript is earlier than 0:7.05-32.1.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050081003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081003" version="503" comment="ghostscript is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081004" version="503" comment="ghostscript-devel is earlier than 0:7.05-32.1.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050081003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081005" version="503" comment="ghostscript-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081006" version="503" comment="hpijs is earlier than 0:1.3-32.1.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050081004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050081007" version="503" comment="hpijs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050081004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050090002" version="502" comment="htdig is earlier than 3:3.2.0b6-3.40.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050090002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050090003" version="502" comment="htdig is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050090002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050090004" version="502" comment="htdig-web is earlier than 3:3.2.0b6-3.40.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050090003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050090005" version="502" comment="htdig-web is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050090003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092002" version="502" comment="kernel is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092004" version="502" comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092005" version="502" comment="kernel-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092006" version="502" comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092008" version="502" comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092010" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092011" version="502" comment="kernel-smp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092012" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092014" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050092003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050092015" version="502" comment="kernel-hugemem-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050094002" version="502" comment="thunderbird is earlier than 0:1.0-1.1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050094002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050094003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050094003" version="502" comment="thunderbird is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050094002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050099002" version="502" comment="squirrelmail is earlier than 0:1.4.3a-9.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050099002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050099003" version="502" comment="squirrelmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050099002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050100002" version="502" comment="mod_python is earlier than 0:3.1.3-5.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050100003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050100003" version="502" comment="mod_python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102002" version="502" comment="dbus is earlier than 0:0.22-12.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102003" version="502" comment="dbus is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102004" version="502" comment="dbus-devel is earlier than 0:0.22-12.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102005" version="502" comment="dbus-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102006" version="502" comment="dbus-glib is earlier than 0:0.22-12.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102007" version="502" comment="dbus-glib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102008" version="502" comment="dbus-x11 is earlier than 0:0.22-12.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102009" version="502" comment="dbus-x11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102010" version="502" comment="dbus-python is earlier than 0:0.22-12.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050102011" version="502" comment="dbus-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050102006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050103002" version="502" comment="perl is earlier than 3:5.8.5-12.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050103003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050103003" version="502" comment="perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050103004" version="502" comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050103004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050103005" version="502" comment="perl-suidperl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050104002" version="502" comment="mod_python is earlier than 0:3.0.3-5.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105002" version="502" comment="perl is earlier than 2:5.8.0-89.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050105003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105004" version="502" comment="perl-CPAN is earlier than 2:1.61-89.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050105004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105005" version="502" comment="perl-CPAN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105006" version="502" comment="perl-CGI is earlier than 2:2.81-89.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050105005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105007" version="502" comment="perl-CGI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105008" version="502" comment="perl-DB_File is earlier than 2:1.804-89.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050105006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105009" version="502" comment="perl-DB_File is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050105010" version="502" comment="perl-suidperl is earlier than 2:5.8.0-89.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050105003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106002" version="502" comment="openssh is earlier than 0:3.6.1p2-33.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106003" version="502" comment="openssh is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106004" version="502" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106005" version="502" comment="openssh-clients is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106006" version="502" comment="openssh-server is earlier than 0:3.6.1p2-33.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106007" version="502" comment="openssh-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106008" version="502" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106009" version="502" comment="openssh-askpass is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106010" version="502" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050106011" version="502" comment="openssh-askpass-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108002" version="502" comment="python is earlier than 0:2.3.4-14.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108003" version="502" comment="python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108004" version="502" comment="python-devel is earlier than 0:2.3.4-14.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108005" version="502" comment="python-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108006" version="502" comment="python-tools is earlier than 0:2.3.4-14.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108007" version="502" comment="python-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108008" version="502" comment="python-docs is earlier than 0:2.3.4-14.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108009" version="502" comment="python-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108010" version="502" comment="tkinter is earlier than 0:2.3.4-14.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050108011" version="502" comment="tkinter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050109002" version="502" comment="python is earlier than 0:2.2.3-6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050109003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050109004" version="502" comment="python-devel is earlier than 0:2.2.3-6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050109003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050109006" version="502" comment="python-tools is earlier than 0:2.2.3-6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050109003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050109008" version="502" comment="python-docs is earlier than 0:2.2.3-6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050109003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050109010" version="502" comment="tkinter is earlier than 0:2.2.3-6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050108006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050109003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110002" version="502" comment="emacs is earlier than 0:21.3-19.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050110003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110003" version="502" comment="emacs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110004" version="502" comment="emacs-nox is earlier than 0:21.3-19.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050110003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110005" version="502" comment="emacs-nox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110006" version="502" comment="emacs-common is earlier than 0:21.3-19.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050110003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110007" version="502" comment="emacs-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110008" version="502" comment="emacs-el is earlier than 0:21.3-19.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050110003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110009" version="502" comment="emacs-el is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110010" version="502" comment="emacs-leim is earlier than 0:21.3-19.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050110003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050110011" version="502" comment="emacs-leim is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050112002" version="502" comment="emacs is earlier than 0:21.3-4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050112003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050112004" version="502" comment="emacs-el is earlier than 0:21.3-4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050112003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050112006" version="502" comment="emacs-leim is earlier than 0:21.3-4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050112003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050122002" version="502" comment="vim is earlier than 1:6.3.046-0.30E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050122004" version="502" comment="vim-common is earlier than 1:6.3.046-0.30E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050122006" version="502" comment="vim-minimal is earlier than 1:6.3.046-0.30E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050122008" version="502" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050122010" version="502" comment="vim-X11 is earlier than 1:6.3.046-0.30E.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128002" version="502" comment="imap is earlier than 1:2002d-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050128003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128003" version="502" comment="imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128004" version="502" comment="imap-devel is earlier than 1:2002d-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050128003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128005" version="502" comment="imap-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128006" version="502" comment="imap-utils is earlier than 1:2002d-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050128003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050128007" version="502" comment="imap-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050132002" version="502" comment="cups is earlier than 1:1.1.17-13.3.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050132004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050132006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133002" version="502" comment="xemacs is earlier than 0:21.4.15-10.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050133003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133003" version="502" comment="xemacs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133004" version="502" comment="xemacs-common is earlier than 0:21.4.15-10.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050133003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133005" version="502" comment="xemacs-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133006" version="502" comment="xemacs-nox is earlier than 0:21.4.15-10.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050133003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133007" version="502" comment="xemacs-nox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133008" version="502" comment="xemacs-el is earlier than 0:21.4.15-10.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050133003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133009" version="502" comment="xemacs-el is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133010" version="502" comment="xemacs-info is earlier than 0:21.4.15-10.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050133003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050133011" version="502" comment="xemacs-info is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050134002" version="502" comment="xemacs is earlier than 0:21.4.13-8.ent.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050134004" version="502" comment="xemacs-el is earlier than 0:21.4.13-8.ent.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050134006" version="502" comment="xemacs-info is earlier than 0:21.4.13-8.ent.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050133006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050135002" version="502" comment="squirrelmail is earlier than 0:1.4.3a-9.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050099002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050135003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050136002" version="503" comment="mailman is earlier than 3:2.1.5-24.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050136003" version="503" comment="mailman is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050137002" version="502" comment="mailman is earlier than 3:2.1.5-31.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050137003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138002" version="502" comment="postgresql is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138003" version="502" comment="postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138004" version="502" comment="postgresql-libs is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138005" version="502" comment="postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138006" version="502" comment="postgresql-server is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138007" version="502" comment="postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138008" version="502" comment="postgresql-docs is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138009" version="502" comment="postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138010" version="502" comment="postgresql-contrib is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138011" version="502" comment="postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138012" version="502" comment="postgresql-devel is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138013" version="502" comment="postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138014" version="502" comment="postgresql-pl is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138015" version="502" comment="postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138016" version="502" comment="postgresql-tcl is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138017" version="502" comment="postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138018" version="502" comment="postgresql-python is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138019" version="502" comment="postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138020" version="502" comment="postgresql-jdbc is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138021" version="502" comment="postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138022" version="502" comment="postgresql-test is earlier than 0:7.4.7-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050138023" version="502" comment="postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141002" version="502" comment="rh-postgresql is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141003" version="502" comment="rh-postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141004" version="502" comment="rh-postgresql-libs is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141005" version="502" comment="rh-postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141006" version="502" comment="rh-postgresql-server is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141007" version="502" comment="rh-postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141008" version="502" comment="rh-postgresql-docs is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141009" version="502" comment="rh-postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141010" version="502" comment="rh-postgresql-contrib is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141011" version="502" comment="rh-postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141012" version="502" comment="rh-postgresql-devel is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141013" version="502" comment="rh-postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141014" version="502" comment="rh-postgresql-pl is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141015" version="502" comment="rh-postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141016" version="502" comment="rh-postgresql-tcl is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141017" version="502" comment="rh-postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141018" version="502" comment="rh-postgresql-python is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141019" version="502" comment="rh-postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141020" version="502" comment="rh-postgresql-jdbc is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141021" version="502" comment="rh-postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141022" version="502" comment="rh-postgresql-test is earlier than 0:7.3.9-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050141003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050141023" version="502" comment="rh-postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050152002" version="502" comment="postfix is earlier than 2:2.1.5-4.2.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050152002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050152003" version="502" comment="postfix is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050152002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050152004" version="502" comment="postfix-pflogsumm is earlier than 2:2.1.5-4.2.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050152003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050152005" version="502" comment="postfix-pflogsumm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050152003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050165002" version="502" comment="rsh is earlier than 0:0.17-25.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050165003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050165004" version="502" comment="rsh-server is earlier than 0:0.17-25.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050074003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050165003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050173002" version="502" comment="squid is earlier than 7:2.5.STABLE3-6.3E.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050173003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050175002" version="502" comment="kdenetwork is earlier than 7:3.1.3-1.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050175003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050175003" version="502" comment="kdenetwork is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050175004" version="502" comment="kdenetwork-devel is earlier than 7:3.1.3-1.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050175003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050175005" version="502" comment="kdenetwork-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050176002" version="502" comment="firefox is earlier than 0:1.0.1-1.4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050176003" version="502" comment="firefox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198002" version="502" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198003" version="502" comment="xorg-x11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198004" version="502" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198005" version="502" comment="xorg-x11-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198006" version="502" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198007" version="502" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198008" version="502" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198009" version="502" comment="xorg-x11-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198010" version="502" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198011" version="502" comment="xorg-x11-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198012" version="502" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198013" version="502" comment="xorg-x11-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198014" version="502" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198015" version="502" comment="xorg-x11-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198016" version="502" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198017" version="502" comment="xorg-x11-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198018" version="502" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198019" version="502" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198020" version="502" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198021" version="502" comment="xorg-x11-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198022" version="502" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198023" version="502" comment="xorg-x11-Xdmx is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198024" version="502" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198025" version="502" comment="xorg-x11-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198026" version="502" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198027" version="502" comment="xorg-x11-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198028" version="502" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198029" version="502" comment="xorg-x11-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198030" version="502" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198031" version="502" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198032" version="502" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198033" version="502" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198034" version="502" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198035" version="502" comment="xorg-x11-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198036" version="502" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198037" version="502" comment="xorg-x11-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198038" version="502" comment="fonts-xorg is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198039" version="502" comment="fonts-xorg is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198040" version="502" comment="fonts-xorg-base is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198041" version="502" comment="fonts-xorg-base is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198042" version="502" comment="fonts-xorg-truetype is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198043" version="502" comment="fonts-xorg-truetype is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198044" version="502" comment="fonts-xorg-syriac is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198045" version="502" comment="fonts-xorg-syriac is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198046" version="502" comment="fonts-xorg-75dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198047" version="502" comment="fonts-xorg-75dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198048" version="502" comment="fonts-xorg-100dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198049" version="502" comment="fonts-xorg-100dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198050" version="502" comment="fonts-xorg-ISO8859-2-75dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198051" version="502" comment="fonts-xorg-ISO8859-2-75dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198052" version="502" comment="fonts-xorg-ISO8859-2-100dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198053" version="502" comment="fonts-xorg-ISO8859-2-100dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198054" version="502" comment="fonts-xorg-ISO8859-9-75dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198055" version="502" comment="fonts-xorg-ISO8859-9-75dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198056" version="502" comment="fonts-xorg-ISO8859-9-100dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198057" version="502" comment="fonts-xorg-ISO8859-9-100dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198058" version="502" comment="fonts-xorg-ISO8859-14-75dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198059" version="502" comment="fonts-xorg-ISO8859-14-75dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198060" version="502" comment="fonts-xorg-ISO8859-14-100dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198061" version="502" comment="fonts-xorg-ISO8859-14-100dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198062" version="502" comment="fonts-xorg-ISO8859-15-75dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198063" version="502" comment="fonts-xorg-ISO8859-15-75dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198064" version="502" comment="fonts-xorg-ISO8859-15-100dpi is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198065" version="502" comment="fonts-xorg-ISO8859-15-100dpi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198066" version="502" comment="fonts-xorg-cyrillic is earlier than 0:6.8.1.1-1.EL.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050198004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050198067" version="502" comment="fonts-xorg-cyrillic is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050201002" version="502" comment="squid is earlier than 7:2.5.STABLE6-3.4E.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050201003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050213002" version="502" comment="xpdf is earlier than 1:2.02-9.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050213003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050215002" version="502" comment="gaim is earlier than 1:1.1.4-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050215003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050215003" version="502" comment="gaim is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050215005" version="502" comment="gaim is earlier than 1:1.1.4-1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050215005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050232002" version="502" comment="ipsec-tools is earlier than 0:0.2.5-0.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050232002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050232003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050232003" version="502" comment="ipsec-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050232002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050232005" version="502" comment="ipsec-tools is earlier than 0:0.3.3-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050232002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050232005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050235002" version="502" comment="mailman is earlier than 3:2.1.5-25.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050235003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050235005" version="502" comment="mailman is earlier than 3:2.1.5-33.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050235005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050238002" version="502" comment="evolution is earlier than 0:1.4.5-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050238003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050238003" version="502" comment="evolution is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050238004" version="502" comment="evolution-devel is earlier than 0:1.4.5-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050238003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050238005" version="502" comment="evolution-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256002" version="502" comment="glibc is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256003" version="502" comment="glibc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256004" version="502" comment="glibc-devel is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256005" version="502" comment="glibc-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256006" version="502" comment="glibc-headers is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256007" version="502" comment="glibc-headers is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256008" version="502" comment="nptl-devel is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256009" version="502" comment="nptl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256010" version="502" comment="glibc-profile is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256011" version="502" comment="glibc-profile is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256012" version="502" comment="glibc-common is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256013" version="502" comment="glibc-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256014" version="502" comment="nscd is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256015" version="502" comment="nscd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256016" version="502" comment="glibc-debug is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256017" version="502" comment="glibc-debug is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256018" version="502" comment="glibc-utils is earlier than 0:2.3.2-95.33" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050256003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050256019" version="502" comment="glibc-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050256010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050267002" version="502" comment="evolution is earlier than 0:1.4.5-16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050267004" version="502" comment="evolution-devel is earlier than 0:1.4.5-16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050267007" version="502" comment="evolution is earlier than 0:2.0.2-16.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050267005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050267008" version="502" comment="evolution-devel is earlier than 0:2.0.2-16.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050267005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050271002" version="502" comment="HelixPlayer is earlier than 1:1.0.3-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050271003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050271003" version="502" comment="HelixPlayer is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277002" version="502" comment="mozilla is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277004" version="502" comment="mozilla-chat is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277006" version="502" comment="mozilla-devel is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277008" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277010" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277012" version="502" comment="mozilla-mail is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277014" version="502" comment="mozilla-nspr is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277016" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277018" version="502" comment="mozilla-nss is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050277020" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.3-19.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050277003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293002" version="502" comment="kernel is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293004" version="502" comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293006" version="502" comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293008" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293010" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293012" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293014" version="502" comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293016" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050293018" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050293003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294002" version="502" comment="kernel is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294004" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294006" version="502" comment="kernel-source is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294008" version="502" comment="kernel-doc is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294010" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294012" version="502" comment="kernel-smp is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294014" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294016" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050294018" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-32.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050294003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050300002" version="502" comment="libexif is earlier than 0:0.5.12-5.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050300003" version="502" comment="libexif is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050300004" version="502" comment="libexif-devel is earlier than 0:0.5.12-5.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050300005" version="502" comment="libexif-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050306002" version="502" comment="ethereal is earlier than 0:0.10.10-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050306003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050306004" version="502" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050306003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050306007" version="502" comment="ethereal is earlier than 0:0.10.10-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050306005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050306008" version="502" comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050306005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050307002" version="502" comment="kdelibs is earlier than 6:3.1.3-6.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050307003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050307004" version="502" comment="kdelibs-devel is earlier than 6:3.1.3-6.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050307003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050320002" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050320003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050320004" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050320003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050320006" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050320003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050320008" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050320003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050320010" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050320003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323002" version="503" comment="mozilla is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323004" version="503" comment="mozilla-nspr is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323006" version="503" comment="mozilla-nspr-devel is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323008" version="503" comment="mozilla-nss is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323010" version="503" comment="mozilla-nss-devel is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323012" version="503" comment="mozilla-devel is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323014" version="503" comment="mozilla-mail is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323016" version="503" comment="mozilla-chat is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323018" version="503" comment="mozilla-js-debugger is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050323020" version="503" comment="mozilla-dom-inspector is earlier than 37:1.4.4-1.3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050325002" version="502" comment="kdelibs is earlier than 6:3.3.1-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050325004" version="502" comment="kdelibs-devel is earlier than 6:3.3.1-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327002" version="502" comment="telnet is earlier than 1:0.17-26.EL3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050327003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327003" version="502" comment="telnet is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327004" version="502" comment="telnet-server is earlier than 1:0.17-26.EL3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050327003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327005" version="502" comment="telnet-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327007" version="502" comment="telnet is earlier than 1:0.17-31.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050327005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050327008" version="502" comment="telnet-server is earlier than 1:0.17-31.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050327005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330002" version="502" comment="krb5 is earlier than 0:1.2.7-42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330004" version="502" comment="krb5-devel is earlier than 0:1.2.7-42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330006" version="502" comment="krb5-libs is earlier than 0:1.2.7-42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330008" version="502" comment="krb5-server is earlier than 0:1.2.7-42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330010" version="502" comment="krb5-workstation is earlier than 0:1.2.7-42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330013" version="502" comment="krb5 is earlier than 0:1.3.4-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330014" version="502" comment="krb5-devel is earlier than 0:1.3.4-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330015" version="502" comment="krb5-libs is earlier than 0:1.3.4-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330016" version="502" comment="krb5-server is earlier than 0:1.3.4-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050330017" version="502" comment="krb5-workstation is earlier than 0:1.3.4-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050330005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331002" version="502" comment="XFree86 is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331003" version="502" comment="XFree86 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331004" version="502" comment="XFree86-devel is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331005" version="502" comment="XFree86-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331006" version="502" comment="XFree86-font-utils is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331007" version="502" comment="XFree86-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331008" version="502" comment="XFree86-xfs is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331009" version="502" comment="XFree86-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331010" version="502" comment="XFree86-twm is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331011" version="502" comment="XFree86-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331012" version="502" comment="XFree86-xdm is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331013" version="502" comment="XFree86-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331014" version="502" comment="XFree86-libs is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331015" version="502" comment="XFree86-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331016" version="502" comment="XFree86-libs-data is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331017" version="502" comment="XFree86-libs-data is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331018" version="502" comment="XFree86-base-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331019" version="502" comment="XFree86-base-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331020" version="502" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331021" version="502" comment="XFree86-truetype-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331022" version="502" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331023" version="502" comment="XFree86-syriac-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331024" version="502" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331025" version="502" comment="XFree86-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331026" version="502" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331027" version="502" comment="XFree86-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331028" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331029" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331030" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331031" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331032" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331033" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331034" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331035" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331036" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331037" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331038" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331039" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331040" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331041" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331042" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331043" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331044" version="502" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331045" version="502" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331046" version="502" comment="XFree86-doc is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331047" version="502" comment="XFree86-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331048" version="502" comment="XFree86-Xnest is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331049" version="502" comment="XFree86-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331050" version="502" comment="XFree86-Xvfb is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331051" version="502" comment="XFree86-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331052" version="502" comment="XFree86-tools is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331053" version="502" comment="XFree86-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331054" version="502" comment="XFree86-xauth is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331055" version="502" comment="XFree86-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331056" version="502" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331057" version="502" comment="XFree86-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331058" version="502" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331059" version="502" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331060" version="502" comment="XFree86-sdk is earlier than 0:4.3.0-81.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050331061" version="502" comment="XFree86-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050332002" version="502" comment="xloadimage is earlier than 0:4.1-34.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050332003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050332003" version="502" comment="xloadimage is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050332005" version="502" comment="xloadimage is earlier than 0:4.1-34.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050332005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334002" version="502" comment="mysql is earlier than 0:3.23.58-15.RHEL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334003" version="502" comment="mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334004" version="502" comment="mysql-server is earlier than 0:3.23.58-15.RHEL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334005" version="502" comment="mysql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334006" version="502" comment="mysql-devel is earlier than 0:3.23.58-15.RHEL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334007" version="502" comment="mysql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334008" version="502" comment="mysql-bench is earlier than 0:3.23.58-15.RHEL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334009" version="502" comment="mysql-bench is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334011" version="502" comment="mysql is earlier than 0:4.1.10a-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334012" version="502" comment="mysql-server is earlier than 0:4.1.10a-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334013" version="502" comment="mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050334014" version="502" comment="mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050334005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335002" version="503" comment="mozilla is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335004" version="503" comment="mozilla-nspr is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335006" version="503" comment="mozilla-nspr-devel is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335008" version="503" comment="mozilla-nss is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335010" version="503" comment="mozilla-nss-devel is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335012" version="503" comment="mozilla-devel is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335014" version="503" comment="mozilla-mail is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335016" version="503" comment="mozilla-chat is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335018" version="503" comment="mozilla-js-debugger is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335020" version="503" comment="mozilla-dom-inspector is earlier than 37:1.7.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335022" version="503" comment="devhelp is earlier than 0:0.9.2-2.4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335023" version="503" comment="devhelp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335024" version="503" comment="devhelp-devel is earlier than 0:0.9.2-2.4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335025" version="503" comment="devhelp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335026" version="503" comment="evolution is earlier than 0:2.0.2-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050335028" version="503" comment="evolution-devel is earlier than 0:2.0.2-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050335005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050336002" version="502" comment="firefox is earlier than 0:1.0.2-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050336003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050337002" version="502" comment="thunderbird is earlier than 0:1.0.2-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050094002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050336003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340002" version="502" comment="curl is earlier than 0:7.10.6-6.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050340003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340003" version="502" comment="curl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340004" version="502" comment="curl-devel is earlier than 0:7.10.6-6.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050340003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340005" version="502" comment="curl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340007" version="502" comment="curl is earlier than 0:7.12.1-5.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050340005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050340008" version="502" comment="curl-devel is earlier than 0:7.12.1-5.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050340005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343002" version="502" comment="gdk-pixbuf is earlier than 1:0.22.0-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050343003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343003" version="502" comment="gdk-pixbuf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343004" version="502" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050343003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343005" version="502" comment="gdk-pixbuf-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343006" version="502" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050343003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343007" version="502" comment="gdk-pixbuf-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343009" version="502" comment="gdk-pixbuf is earlier than 1:0.22.0-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050343005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050343010" version="502" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050343005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344002" version="502" comment="gtk2 is earlier than 0:2.2.4-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050344003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344003" version="502" comment="gtk2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344004" version="502" comment="gtk2-devel is earlier than 0:2.2.4-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050344003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344005" version="502" comment="gtk2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344007" version="502" comment="gtk2 is earlier than 0:2.4.13-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050344005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050344008" version="502" comment="gtk2-devel is earlier than 0:2.4.13-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050344005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050345002" version="503" comment="slocate is earlier than 0:2.7-3.RHEL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050345003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050345003" version="503" comment="slocate is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050346002" version="502" comment="slocate is earlier than 0:2.7-13.el4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354002" version="502" comment="tetex is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354004" version="502" comment="tetex-latex is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354006" version="502" comment="tetex-xdvi is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354008" version="502" comment="tetex-dvips is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354010" version="502" comment="tetex-afm is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354012" version="502" comment="tetex-fonts is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050354014" version="502" comment="tetex-doc is earlier than 0:1.0.7-67.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050026008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050354003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050357002" version="502" comment="gzip is earlier than 0:1.3.3-12.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050357002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050357003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050357003" version="502" comment="gzip is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050357002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050357005" version="502" comment="gzip is earlier than 0:1.3.3-15.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050357002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050357005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050358002" version="502" comment="exim is earlier than 0:4.43-1.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050358004" version="502" comment="exim-mon is earlier than 0:4.43-1.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050358006" version="502" comment="exim-doc is earlier than 0:4.43-1.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050358008" version="502" comment="exim-sa is earlier than 0:4.43-1.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050025005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050361002" version="502" comment="vixie-cron is earlier than 4:4.1-36.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050361003" version="502" comment="vixie-cron is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050365002" version="502" comment="gaim is earlier than 1:1.2.1-4.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050365003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050365005" version="502" comment="gaim is earlier than 1:1.2.1-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050365005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366002" version="503" comment="kernel is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366004" version="503" comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366006" version="503" comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366008" version="503" comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366010" version="503" comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366012" version="503" comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050366014" version="503" comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050366003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373002" version="502" comment="net-snmp is earlier than 0:5.0.9-2.30E.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050373003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373003" version="502" comment="net-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373004" version="502" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050373003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373005" version="502" comment="net-snmp-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373006" version="502" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050373003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373007" version="502" comment="net-snmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373008" version="502" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050373003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373009" version="502" comment="net-snmp-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373010" version="502" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050373003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050373011" version="502" comment="net-snmp-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375002" version="502" comment="openoffice.org is earlier than 0:1.1.2-24.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375003" version="502" comment="openoffice.org is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375004" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-24.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375005" version="502" comment="openoffice.org-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375006" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375007" version="502" comment="openoffice.org-i18n is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375009" version="502" comment="openoffice.org is earlier than 0:1.1.2-24.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375010" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-24.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375011" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-24.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375012" version="502" comment="openoffice.org-kde is earlier than 0:1.1.2-24.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050375005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050375013" version="502" comment="openoffice.org-kde is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050375005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050377002" version="502" comment="sharutils is earlier than 0:4.2.1-16.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050377002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050377003" version="502" comment="sharutils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050377002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050377005" version="502" comment="sharutils is earlier than 0:4.2.1-22.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050377002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050377005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050378002" version="502" comment="cpio is earlier than 0:2.5-4.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050073002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050378003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050378005" version="502" comment="cpio is earlier than 0:2.5-8.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050073002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050378005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381002" version="502" comment="nasm is earlier than 0:0.98.35-3.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381003" version="502" comment="nasm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381004" version="502" comment="nasm-doc is earlier than 0:0.98.35-3.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381005" version="502" comment="nasm-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381006" version="502" comment="nasm-rdoff is earlier than 0:0.98.35-3.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381007" version="502" comment="nasm-rdoff is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381009" version="502" comment="nasm is earlier than 0:0.98.38-3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381010" version="502" comment="nasm-doc is earlier than 0:0.98.38-3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050381011" version="502" comment="nasm-rdoff is earlier than 0:0.98.38-3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050381004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050381005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050383002" version="502" comment="firefox is earlier than 0:1.0.3-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050383003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384002" version="502" comment="mozilla is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384004" version="502" comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384006" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384008" version="502" comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384010" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384012" version="502" comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384014" version="502" comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384016" version="502" comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384018" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050384020" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386002" version="502" comment="mozilla is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386004" version="502" comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386006" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386008" version="502" comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386010" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386012" version="502" comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386014" version="502" comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386016" version="502" comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386018" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386020" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386022" version="502" comment="devhelp is earlier than 0:0.9.2-2.4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050386024" version="502" comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050386004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050387002" version="502" comment="cvs is earlier than 0:1.11.2-27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050387002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050387003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050387003" version="502" comment="cvs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050387002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050387005" version="502" comment="cvs is earlier than 0:1.11.17-7.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050387002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050387005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050392002" version="504" comment="HelixPlayer is earlier than 1:1.0.4-1.1.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050392003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050393002" version="502" comment="kdelibs is earlier than 6:3.3.1-3.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050393003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050393004" version="502" comment="kdelibs-devel is earlier than 6:3.3.1-3.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050393003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050395002" version="502" comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050395003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050395004" version="502" comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050395003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050395006" version="502" comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050395003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050395008" version="502" comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050395003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050395010" version="502" comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050373006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050395003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396002" version="502" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396004" version="502" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396006" version="502" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396008" version="502" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396010" version="502" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396012" version="502" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396014" version="502" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396016" version="502" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396018" version="502" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396020" version="502" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396022" version="502" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396024" version="502" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396026" version="502" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396028" version="502" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396030" version="502" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396032" version="502" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396034" version="502" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050396036" version="502" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050198019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050396003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050397002" version="502" comment="evolution is earlier than 0:2.0.2-16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050397003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050397004" version="502" comment="evolution-devel is earlier than 0:2.0.2-16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050397003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405002" version="502" comment="php is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405004" version="502" comment="php-devel is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405006" version="502" comment="php-imap is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405008" version="502" comment="php-ldap is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405010" version="502" comment="php-mysql is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405012" version="502" comment="php-pgsql is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050405014" version="502" comment="php-odbc is earlier than 0:4.3.2-23.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050405003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406002" version="502" comment="php is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406004" version="502" comment="php-devel is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406006" version="502" comment="php-pear is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406008" version="502" comment="php-imap is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406010" version="502" comment="php-ldap is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406012" version="502" comment="php-mysql is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406014" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406016" version="502" comment="php-odbc is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406018" version="502" comment="php-snmp is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406020" version="502" comment="php-domxml is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406022" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406024" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406026" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050406028" version="502" comment="php-gd is earlier than 0:4.3.9-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050406003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408002" version="502" comment="cyrus-imapd is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408003" version="502" comment="cyrus-imapd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408004" version="502" comment="cyrus-imapd-murder is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408005" version="502" comment="cyrus-imapd-murder is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408006" version="502" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408007" version="502" comment="cyrus-imapd-nntp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408008" version="502" comment="cyrus-imapd-devel is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408009" version="502" comment="cyrus-imapd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408010" version="502" comment="perl-Cyrus is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408011" version="502" comment="perl-Cyrus is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408012" version="502" comment="cyrus-imapd-utils is earlier than 0:2.2.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050408013" version="502" comment="cyrus-imapd-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050408007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050410002" version="502" comment="gftp is earlier than 1:2.0.14-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050410002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050410003" version="502" comment="gftp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050410002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050410005" version="502" comment="gftp is earlier than 1:2.0.17-5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050410002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050410005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412002" version="502" comment="openmotif21 is earlier than 0:2.1.30-9.RHEL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412003" version="502" comment="openmotif21 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412004" version="502" comment="openmotif is earlier than 0:2.2.3-5.RHEL3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412005" version="502" comment="openmotif is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412006" version="502" comment="openmotif-devel is earlier than 0:2.2.3-5.RHEL3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412007" version="502" comment="openmotif-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412009" version="502" comment="openmotif21 is earlier than 0:2.1.30-11.RHEL4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412010" version="502" comment="openmotif is earlier than 0:2.2.3-9.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050412011" version="502" comment="openmotif-devel is earlier than 0:2.2.3-9.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050412004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050412007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413002" version="502" comment="ImageMagick is earlier than 0:5.5.6-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413004" version="502" comment="ImageMagick-devel is earlier than 0:5.5.6-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413006" version="502" comment="ImageMagick-perl is earlier than 0:5.5.6-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413008" version="502" comment="ImageMagick-c++ is earlier than 0:5.5.6-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413010" version="502" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413013" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413014" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413015" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413016" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050413017" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050413005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050415002" version="502" comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050415003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050415005" version="502" comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050415005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417002" version="503" comment="tcpdump is earlier than 14:3.8.2-9.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050417003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417003" version="503" comment="tcpdump is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417004" version="503" comment="libpcap is earlier than 14:0.8.3-9.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050417004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417005" version="503" comment="libpcap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417006" version="503" comment="arpwatch is earlier than 14:2.1a13-9.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050417005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050417007" version="503" comment="arpwatch is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420002" version="503" comment="kernel is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420004" version="503" comment="kernel-devel is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420006" version="503" comment="kernel-doc is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420008" version="503" comment="kernel-smp is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420010" version="503" comment="kernel-smp-devel is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420012" version="503" comment="kernel-hugemem is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050420014" version="503" comment="kernel-hugemem-devel is earlier than 0:2.6.9-11.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050421002" version="503" comment="tcpdump is earlier than 14:3.7.2-7.E3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050421003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050421004" version="503" comment="libpcap is earlier than 14:0.7.2-7.E3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050421004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050421006" version="503" comment="arpwatch is earlier than 14:2.1a11-7.E3.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050421005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050427002" version="502" comment="ethereal is earlier than 0:0.10.11-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050427003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050427004" version="502" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050427003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050427007" version="502" comment="ethereal is earlier than 0:0.10.11-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050427005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050427008" version="502" comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050427005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050429002" version="502" comment="gaim is earlier than 1:1.2.1-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050429003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050429005" version="502" comment="gaim is earlier than 1:1.2.1-6.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050429005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050430002" version="502" comment="gnutls is earlier than 0:1.0.20-3.2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050430002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050430003" version="502" comment="gnutls is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050430002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050430004" version="502" comment="gnutls-devel is earlier than 0:1.0.20-3.2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050430003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050430005" version="502" comment="gnutls-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050430003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433002" version="502" comment="rh-postgresql is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433004" version="502" comment="rh-postgresql-libs is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433006" version="502" comment="rh-postgresql-server is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433008" version="502" comment="rh-postgresql-docs is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433010" version="502" comment="rh-postgresql-contrib is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433012" version="502" comment="rh-postgresql-devel is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433014" version="502" comment="rh-postgresql-pl is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433016" version="502" comment="rh-postgresql-tcl is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433018" version="502" comment="rh-postgresql-python is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433020" version="502" comment="rh-postgresql-jdbc is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433022" version="502" comment="rh-postgresql-test is earlier than 0:7.3.10-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050141012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433025" version="502" comment="postgresql is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433027" version="502" comment="postgresql-libs is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433029" version="502" comment="postgresql-server is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433031" version="502" comment="postgresql-docs is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433033" version="502" comment="postgresql-contrib is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433035" version="502" comment="postgresql-devel is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433037" version="502" comment="postgresql-pl is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433039" version="502" comment="postgresql-tcl is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433041" version="502" comment="postgresql-python is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433043" version="502" comment="postgresql-jdbc is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050433045" version="502" comment="postgresql-test is earlier than 0:7.4.8-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050138012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050433005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050434002" version="502" comment="firefox is earlier than 0:1.0.4-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050434003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435002" version="502" comment="mozilla is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435004" version="502" comment="mozilla-chat is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435006" version="502" comment="mozilla-devel is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435008" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435010" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435012" version="502" comment="mozilla-mail is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435014" version="502" comment="mozilla-nspr is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435016" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435018" version="502" comment="mozilla-nss is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435020" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435023" version="502" comment="mozilla is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435024" version="502" comment="mozilla-chat is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435025" version="502" comment="mozilla-devel is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435026" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435027" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435028" version="502" comment="mozilla-mail is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435029" version="502" comment="mozilla-nspr is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435030" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435031" version="502" comment="mozilla-nss is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435032" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.8-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435033" version="502" comment="devhelp is earlier than 0:0.9.2-2.4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050435035" version="502" comment="devhelp-devel is earlier than 0:0.9.2-2.4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050435006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472002" version="502" comment="kernel is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472004" version="502" comment="kernel-source is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472006" version="502" comment="kernel-doc is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472008" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472010" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472012" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472014" version="502" comment="kernel-smp is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472016" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050472018" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-32.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050472003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474002" version="503" comment="bzip2 is earlier than 0:1.0.2-11.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474003" version="503" comment="bzip2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474004" version="503" comment="bzip2-devel is earlier than 0:1.0.2-11.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474005" version="503" comment="bzip2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474006" version="503" comment="bzip2-libs is earlier than 0:1.0.2-11.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474007" version="503" comment="bzip2-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474009" version="503" comment="bzip2 is earlier than 0:1.0.2-13.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474010" version="503" comment="bzip2-devel is earlier than 0:1.0.2-13.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050474011" version="503" comment="bzip2-libs is earlier than 0:1.0.2-13.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050474004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050474005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476002" version="502" comment="openssl096b is earlier than 0:0.9.6b-16.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476003" version="502" comment="openssl096b is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476004" version="502" comment="openssl is earlier than 0:0.9.7a-33.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476005" version="502" comment="openssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476006" version="502" comment="openssl-devel is earlier than 0:0.9.7a-33.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476007" version="502" comment="openssl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476008" version="502" comment="openssl-perl is earlier than 0:0.9.7a-33.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476009" version="502" comment="openssl-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476011" version="502" comment="openssl096b is earlier than 0:0.9.6b-22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476012" version="502" comment="openssl is earlier than 0:0.9.7a-43.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476013" version="502" comment="openssl-devel is earlier than 0:0.9.7a-43.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050476014" version="502" comment="openssl-perl is earlier than 0:0.9.7a-43.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050476007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480002" version="502" comment="ImageMagick is earlier than 0:5.5.6-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480004" version="502" comment="ImageMagick-devel is earlier than 0:5.5.6-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480006" version="502" comment="ImageMagick-perl is earlier than 0:5.5.6-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480008" version="502" comment="ImageMagick-c++ is earlier than 0:5.5.6-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480010" version="502" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480013" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480014" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480015" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480016" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050480017" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050070006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050480005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050498002" version="502" comment="spamassassin is earlier than 0:3.0.4-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050498002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050498003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050498003" version="502" comment="spamassassin is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050498002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050499002" version="502" comment="gedit is earlier than 1:2.2.2-4.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050499002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050499003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050499003" version="502" comment="gedit is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050499002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050499005" version="502" comment="gedit is earlier than 1:2.8.1-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050499002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050499005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050499006" version="502" comment="gedit-devel is earlier than 1:2.8.1-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050499003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050499005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050499007" version="502" comment="gedit-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050499003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501002" version="502" comment="XFree86 is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501004" version="502" comment="XFree86-devel is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501006" version="502" comment="XFree86-font-utils is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501008" version="502" comment="XFree86-xfs is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501010" version="502" comment="XFree86-twm is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501012" version="502" comment="XFree86-xdm is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501014" version="502" comment="XFree86-libs is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501016" version="502" comment="XFree86-libs-data is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501018" version="502" comment="XFree86-base-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501020" version="502" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501022" version="502" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501024" version="502" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501026" version="502" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501028" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501030" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501032" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501034" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501036" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501038" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501040" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501042" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501044" version="502" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501046" version="502" comment="XFree86-doc is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501048" version="502" comment="XFree86-Xnest is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501050" version="502" comment="XFree86-Xvfb is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501052" version="502" comment="XFree86-tools is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501054" version="502" comment="XFree86-xauth is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501056" version="502" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501058" version="502" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050501060" version="502" comment="XFree86-sdk is earlier than 0:4.3.0-95.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050331031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050501003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050502002" version="502" comment="sysreport is earlier than 0:1.3.7.2-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050502002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050502003" version="502" comment="sysreport is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050502002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050502005" version="502" comment="sysreport is earlier than 0:1.3.15-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050502002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050502005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050504002" version="501" comment="telnet is earlier than 1:0.17-26.EL3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050504004" version="501" comment="telnet-server is earlier than 1:0.17-26.EL3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050504007" version="501" comment="telnet is earlier than 1:0.17-31.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050504005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050504008" version="501" comment="telnet-server is earlier than 1:0.17-31.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050504005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050505002" version="502" comment="tcpdump is earlier than 14:3.8.2-10.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050505003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050505004" version="502" comment="libpcap is earlier than 14:0.8.3-10.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050505004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050505006" version="502" comment="arpwatch is earlier than 14:2.1a13-10.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050417004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050505005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506002" version="502" comment="mikmod is earlier than 0:3.1.6-22.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050506003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506003" version="502" comment="mikmod is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506004" version="502" comment="mikmod-devel is earlier than 0:3.1.6-22.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050506003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506005" version="502" comment="mikmod-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506007" version="502" comment="mikmod is earlier than 0:3.1.6-32.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050506005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050506008" version="502" comment="mikmod-devel is earlier than 0:3.1.6-32.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050506003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050506005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514002" version="504" comment="kernel is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514004" version="504" comment="kernel-doc is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514006" version="504" comment="kernel-devel is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514008" version="504" comment="kernel-smp is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514010" version="504" comment="kernel-smp-devel is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514012" version="504" comment="kernel-hugemem is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050514014" version="504" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050517002" version="502" comment="HelixPlayer is earlier than 1:1.0.5-0.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050517003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050518002" version="502" comment="gaim is earlier than 1:1.3.1-0.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050518003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050518005" version="502" comment="gaim is earlier than 1:1.3.1-0.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050518005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524002" version="502" comment="freeradius is earlier than 0:1.0.1-1.1.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524003" version="502" comment="freeradius is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524004" version="502" comment="freeradius-mysql is earlier than 0:1.0.1-1.1.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524005" version="502" comment="freeradius-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524006" version="502" comment="freeradius-postgresql is earlier than 0:1.0.1-1.1.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524007" version="502" comment="freeradius-postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524008" version="502" comment="freeradius-unixODBC is earlier than 0:1.0.1-1.1.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524009" version="502" comment="freeradius-unixODBC is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524011" version="502" comment="freeradius is earlier than 0:1.0.1-3.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524012" version="502" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524013" version="502" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050524014" version="502" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050524005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050524005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050527002" version="502" comment="openssh is earlier than 0:3.9p1-8.RHEL4.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050527003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050527004" version="502" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050527003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050527006" version="502" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050527003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050527008" version="502" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050527003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050527010" version="502" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050527003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050535002" version="505" comment="sudo is earlier than 0:1.6.7p5-1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050535002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050535003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050535003" version="505" comment="sudo is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050535002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050535005" version="505" comment="sudo is earlier than 0:1.6.7p5-30.1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050535002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050535005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543002" version="502" comment="ruby is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543003" version="502" comment="ruby is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543004" version="502" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543005" version="502" comment="ruby-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543006" version="502" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543007" version="502" comment="ruby-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543008" version="502" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543009" version="502" comment="ruby-tcltk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543010" version="502" comment="irb is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543011" version="502" comment="irb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543012" version="502" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543013" version="502" comment="ruby-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543014" version="502" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050543003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050543015" version="502" comment="ruby-mode is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050550002" version="502" comment="openssh is earlier than 0:3.6.1p2-33.30.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050550003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050550004" version="502" comment="openssh-clients is earlier than 0:3.6.1p2-33.30.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050550003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050550006" version="502" comment="openssh-server is earlier than 0:3.6.1p2-33.30.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050550003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050550008" version="502" comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050550003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050550010" version="502" comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050106006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050550003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050562002" version="503" comment="krb5 is earlier than 0:1.2.7-47" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050562004" version="503" comment="krb5-devel is earlier than 0:1.2.7-47" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050562006" version="503" comment="krb5-libs is earlier than 0:1.2.7-47" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050562008" version="503" comment="krb5-server is earlier than 0:1.2.7-47" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050562010" version="503" comment="krb5-workstation is earlier than 0:1.2.7-47" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564002" version="502" comment="php is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564004" version="502" comment="php-devel is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564006" version="502" comment="php-imap is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564008" version="502" comment="php-ldap is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564010" version="502" comment="php-mysql is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564012" version="502" comment="php-pgsql is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564014" version="502" comment="php-odbc is earlier than 0:4.3.2-24.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564017" version="502" comment="php is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564018" version="502" comment="php-devel is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564019" version="502" comment="php-pear is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564021" version="502" comment="php-imap is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564022" version="502" comment="php-ldap is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564023" version="502" comment="php-mysql is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564024" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564025" version="502" comment="php-odbc is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564026" version="502" comment="php-snmp is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564028" version="502" comment="php-domxml is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564030" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564032" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564034" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050564036" version="502" comment="php-gd is earlier than 0:4.3.9-3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050564005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050567002" version="503" comment="krb5 is earlier than 0:1.3.4-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050567003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050567004" version="503" comment="krb5-devel is earlier than 0:1.3.4-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050567003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050567006" version="503" comment="krb5-libs is earlier than 0:1.3.4-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050567003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050567008" version="503" comment="krb5-server is earlier than 0:1.3.4-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050567003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050567010" version="503" comment="krb5-workstation is earlier than 0:1.3.4-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050012006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050567003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050569002" version="502" comment="zlib is earlier than 0:1.2.1.2-1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050569003" version="502" comment="zlib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050569004" version="502" comment="zlib-devel is earlier than 0:1.2.1.2-1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050569005" version="502" comment="zlib-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050571002" version="502" comment="cups is earlier than 1:1.1.17-13.3.29" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050571003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050571004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.29" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050571003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050571006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.29" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050571003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582002" version="502" comment="httpd is earlier than 0:2.0.46-46.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582003" version="502" comment="httpd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582004" version="502" comment="httpd-devel is earlier than 0:2.0.46-46.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582005" version="502" comment="httpd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582006" version="502" comment="mod_ssl is earlier than 0:2.0.46-46.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582007" version="502" comment="mod_ssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582009" version="502" comment="httpd is earlier than 0:2.0.52-12.1.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582010" version="502" comment="httpd-devel is earlier than 0:2.0.52-12.1.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582011" version="502" comment="httpd-manual is earlier than 0:2.0.52-12.1.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582012" version="502" comment="httpd-manual is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582013" version="502" comment="mod_ssl is earlier than 0:2.0.52-12.1.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582014" version="502" comment="httpd-suexec is earlier than 0:2.0.52-12.1.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050582005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050582015" version="502" comment="httpd-suexec is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050584002" version="502" comment="zlib is earlier than 0:1.2.1.2-1.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050584003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050584004" version="502" comment="zlib-devel is earlier than 0:1.2.1.2-1.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050569003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050584003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050586002" version="502" comment="firefox is earlier than 0:1.0.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050586003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587002" version="502" comment="mozilla is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587004" version="502" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587006" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587008" version="502" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587010" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587012" version="502" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587014" version="502" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587016" version="502" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587018" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587020" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587023" version="502" comment="mozilla is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587024" version="502" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587025" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587026" version="502" comment="mozilla-nss is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587027" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587028" version="502" comment="mozilla-devel is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587029" version="502" comment="mozilla-mail is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587030" version="502" comment="mozilla-chat is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587031" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587032" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587033" version="502" comment="devhelp is earlier than 0:0.9.2-2.4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050587035" version="502" comment="devhelp-devel is earlier than 0:0.9.2-2.4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050587006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050595002" version="503" comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050099002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050595005" version="503" comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050099002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050595005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050598002" version="502" comment="sysreport is earlier than 0:1.3.7.2-9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050502002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050598003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050598005" version="502" comment="sysreport is earlier than 0:1.3.15-5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050502002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050598005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050601002" version="502" comment="thunderbird is earlier than 0:1.0.6-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050094002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050586003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608002" version="502" comment="httpd is earlier than 0:2.0.46-46.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608004" version="502" comment="httpd-devel is earlier than 0:2.0.46-46.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608006" version="502" comment="mod_ssl is earlier than 0:2.0.46-46.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608009" version="502" comment="httpd is earlier than 0:2.0.52-12.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608010" version="502" comment="httpd-devel is earlier than 0:2.0.52-12.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608011" version="502" comment="httpd-manual is earlier than 0:2.0.52-12.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608013" version="502" comment="mod_ssl is earlier than 0:2.0.52-12.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050608014" version="502" comment="httpd-suexec is earlier than 0:2.0.52-12.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050582006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050608005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050612002" version="502" comment="kdelibs is earlier than 6:3.3.1-3.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050612003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050612004" version="502" comment="kdelibs-devel is earlier than 6:3.3.1-3.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050009003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050612003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050627002" version="502" comment="gaim is earlier than 1:1.3.1-0.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050627003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050627005" version="502" comment="gaim is earlier than 1:1.3.1-0.el4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050215002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050627005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050639002" version="502" comment="kdenetwork is earlier than 7:3.3.1-2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050639003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050639004" version="502" comment="kdenetwork-devel is earlier than 7:3.3.1-2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050639003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050639006" version="502" comment="kdenetwork-nowlistening is earlier than 7:3.3.1-2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050639004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050639003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050639007" version="502" comment="kdenetwork-nowlistening is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050639004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050640002" version="502" comment="fetchmail is earlier than 0:6.2.0-3.el3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050640002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050640003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050640003" version="502" comment="fetchmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050640002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050640005" version="502" comment="fetchmail is earlier than 0:6.2.5-6.el4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050640002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050640005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050659002" version="502" comment="binutils is earlier than 0:2.14.90.0.4-39" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050659002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050659003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050659003" version="502" comment="binutils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050659002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663002" version="502" comment="kernel is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663004" version="502" comment="kernel-source is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663006" version="502" comment="kernel-doc is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663008" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663010" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663012" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663014" version="502" comment="kernel-smp is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663016" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050663018" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050663003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050670002" version="502" comment="xpdf is earlier than 1:3.00-11.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050670003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050671002" version="502" comment="kdegraphics is earlier than 7:3.3.1-3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050671004" version="502" comment="kdegraphics-devel is earlier than 7:3.3.1-3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050673002" version="502" comment="binutils is earlier than 0:2.15.92.0.2-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050659002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050673003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050674002" version="502" comment="perl is earlier than 3:5.8.5-16.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050674003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050674004" version="502" comment="perl-suidperl is earlier than 3:5.8.5-16.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050674003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050685002" version="502" comment="mysql is earlier than 0:4.1.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050685003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050685004" version="502" comment="mysql-server is earlier than 0:4.1.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050685003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050685006" version="502" comment="mysql-devel is earlier than 0:4.1.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050685003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050685008" version="502" comment="mysql-bench is earlier than 0:4.1.12-3.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050334005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050685003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050687002" version="502" comment="ethereal is earlier than 0:0.10.12-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050687003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050687004" version="502" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050687003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050687007" version="502" comment="ethereal is earlier than 0:0.10.12-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050687005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050687008" version="502" comment="ethereal-gnome is earlier than 0:0.10.12-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050687005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706002" version="502" comment="cups is earlier than 1:1.1.17-13.3.31" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.31" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.31" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706009" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706010" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050706011" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050706005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050708002" version="502" comment="gpdf is earlier than 0:2.8.2-4.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050057002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050708003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050709002" version="502" comment="gdb is earlier than 0:6.3.0.0-1.63" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050709002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050709003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050709003" version="502" comment="gdb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050709002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743002" version="502" comment="netpbm is earlier than 0:9.24-11.30.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743003" version="502" comment="netpbm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743004" version="502" comment="netpbm-devel is earlier than 0:9.24-11.30.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743005" version="502" comment="netpbm-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743006" version="502" comment="netpbm-progs is earlier than 0:9.24-11.30.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743007" version="502" comment="netpbm-progs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743009" version="502" comment="netpbm is earlier than 0:10.25-2.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743010" version="502" comment="netpbm-devel is earlier than 0:10.25-2.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050743011" version="502" comment="netpbm-progs is earlier than 0:10.25-2.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050743005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745002" version="502" comment="vim is earlier than 1:6.3.046-0.30E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745004" version="502" comment="vim-common is earlier than 1:6.3.046-0.30E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745006" version="502" comment="vim-minimal is earlier than 1:6.3.046-0.30E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745008" version="502" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745010" version="502" comment="vim-X11 is earlier than 1:6.3.046-0.30E.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745013" version="502" comment="vim is earlier than 1:6.3.046-0.40E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745014" version="502" comment="vim-common is earlier than 1:6.3.046-0.40E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745015" version="502" comment="vim-minimal is earlier than 1:6.3.046-0.40E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745016" version="502" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050745017" version="502" comment="vim-X11 is earlier than 1:6.3.046-0.40E.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050010006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050745005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748002" version="502" comment="php is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748004" version="502" comment="php-devel is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748006" version="502" comment="php-imap is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748008" version="502" comment="php-ldap is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748010" version="502" comment="php-mysql is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748012" version="502" comment="php-pgsql is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748014" version="502" comment="php-odbc is earlier than 0:4.3.2-25.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748017" version="502" comment="php is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748018" version="502" comment="php-devel is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748019" version="502" comment="php-pear is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748021" version="502" comment="php-imap is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748022" version="502" comment="php-ldap is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748023" version="502" comment="php-mysql is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748024" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748025" version="502" comment="php-odbc is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748026" version="502" comment="php-snmp is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748028" version="502" comment="php-domxml is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748030" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748032" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748034" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050748036" version="502" comment="php-gd is earlier than 0:4.3.9-3.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050748005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751002" version="502" comment="openldap is earlier than 0:2.0.27-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050751003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751003" version="502" comment="openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751004" version="502" comment="openldap-devel is earlier than 0:2.0.27-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050751003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751005" version="502" comment="openldap-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751006" version="502" comment="openldap-servers is earlier than 0:2.0.27-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050751003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751007" version="502" comment="openldap-servers is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751008" version="502" comment="openldap-clients is earlier than 0:2.0.27-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050751003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751009" version="502" comment="openldap-clients is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751010" version="502" comment="nss_ldap is earlier than 0:207-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050751004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050751011" version="502" comment="nss_ldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050756002" version="502" comment="cvs is earlier than 0:1.11.2-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050387002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050756003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050756005" version="502" comment="cvs is earlier than 0:1.11.17-8.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050387002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050756005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761002" version="503" comment="pcre is earlier than 0:3.9-10.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050761003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761003" version="503" comment="pcre is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761004" version="503" comment="pcre-devel is earlier than 0:3.9-10.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050761003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761005" version="503" comment="pcre-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761007" version="503" comment="pcre is earlier than 0:4.5-3.2.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050761005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050761008" version="503" comment="pcre-devel is earlier than 0:4.5-3.2.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050761003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050761005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050766002" version="502" comment="squid is earlier than 7:2.5.STABLE3-6.3E.14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050766003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050766005" version="502" comment="squid is earlier than 7:2.5.STABLE6-3.4E.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050766005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767002" version="502" comment="openldap is earlier than 0:2.2.13-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767004" version="502" comment="openldap-devel is earlier than 0:2.2.13-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767006" version="502" comment="openldap-servers is earlier than 0:2.2.13-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767008" version="502" comment="openldap-servers-sql is earlier than 0:2.2.13-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050767005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767009" version="502" comment="openldap-servers-sql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050767005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767010" version="502" comment="openldap-clients is earlier than 0:2.2.13-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767012" version="502" comment="compat-openldap is earlier than 0:2.1.30-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050767007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767013" version="502" comment="compat-openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050767007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050767014" version="502" comment="nss_ldap is earlier than 0:226-10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050751006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050767005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050768002" version="502" comment="firefox is earlier than 0:1.0.6-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050768003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769002" version="502" comment="mozilla is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769004" version="502" comment="mozilla-nspr is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769006" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769008" version="502" comment="mozilla-nss is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769010" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769012" version="502" comment="mozilla-devel is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769014" version="502" comment="mozilla-mail is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769016" version="502" comment="mozilla-chat is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769018" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769020" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769023" version="502" comment="mozilla is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769024" version="502" comment="mozilla-nspr is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769025" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769026" version="502" comment="mozilla-nss is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769027" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769028" version="502" comment="mozilla-devel is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769029" version="502" comment="mozilla-mail is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769030" version="502" comment="mozilla-chat is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769031" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050769032" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.10-1.4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050769005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050771002" version="502" comment="wget is earlier than 0:1.10.1-1.30E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050771002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050771003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050771003" version="502" comment="wget is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050771002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050771005" version="502" comment="wget is earlier than 0:1.10.1-2.4E.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050771002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050771005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050772002" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050772003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050772004" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050772003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050772006" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050772003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782002" version="502" comment="util-linux is earlier than 0:2.11y-31.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050782003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782003" version="502" comment="util-linux is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782004" version="502" comment="mount is earlier than 0:2.11y-31.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050782003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782005" version="502" comment="mount is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782006" version="502" comment="losetup is earlier than 0:2.11y-31.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050782003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782007" version="502" comment="losetup is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050782009" version="502" comment="util-linux is earlier than 0:2.12a-16.EL4.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050782002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050782005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050785002" version="502" comment="firefox is earlier than 0:1.0.7-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050785003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050788002" version="502" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050788003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789002" version="502" comment="mozilla is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789004" version="502" comment="mozilla-nspr is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789006" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789008" version="502" comment="mozilla-nss is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789010" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789012" version="502" comment="mozilla-devel is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789014" version="502" comment="mozilla-mail is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789016" version="502" comment="mozilla-chat is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789018" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789020" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.1.3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789023" version="502" comment="mozilla is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789024" version="502" comment="mozilla-nspr is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789025" version="502" comment="mozilla-nspr-devel is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789026" version="502" comment="mozilla-nss is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789027" version="502" comment="mozilla-nss-devel is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789028" version="502" comment="mozilla-devel is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789029" version="502" comment="mozilla-mail is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789030" version="502" comment="mozilla-chat is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789031" version="502" comment="mozilla-js-debugger is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789032" version="502" comment="mozilla-dom-inspector is earlier than 37:1.7.12-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789033" version="502" comment="devhelp is earlier than 0:0.9.2-2.4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050789035" version="502" comment="devhelp-devel is earlier than 0:0.9.2-2.4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050335013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050789006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050791002" version="502" comment="thunderbird is earlier than 0:1.0.7-1.4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050094002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050785003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050793002" version="502" comment="netpbm is earlier than 0:10.25-2.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050793003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050793004" version="502" comment="netpbm-devel is earlier than 0:10.25-2.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050793003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050793006" version="502" comment="netpbm-progs is earlier than 0:10.25-2.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050793003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799002" version="503" comment="ruby is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799004" version="503" comment="ruby-libs is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799006" version="503" comment="ruby-devel is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799008" version="503" comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799010" version="503" comment="irb is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799012" version="503" comment="ruby-docs is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799014" version="503" comment="ruby-mode is earlier than 0:1.6.8-9.EL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799017" version="503" comment="ruby is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799018" version="503" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799019" version="503" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799020" version="503" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799021" version="503" comment="irb is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799022" version="503" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050799023" version="503" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050543008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050799005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800002" version="502" comment="openssl096b is earlier than 0:0.9.6b-16.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800004" version="502" comment="openssl is earlier than 0:0.9.7a-33.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800006" version="502" comment="openssl-devel is earlier than 0:0.9.7a-33.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800008" version="502" comment="openssl-perl is earlier than 0:0.9.7a-33.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800011" version="502" comment="openssl096b is earlier than 0:0.9.6b-22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800012" version="502" comment="openssl is earlier than 0:0.9.7a-43.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800013" version="502" comment="openssl-devel is earlier than 0:0.9.7a-43.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050800014" version="502" comment="openssl-perl is earlier than 0:0.9.7a-43.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050800007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050802002" version="502" comment="xloadimage is earlier than 0:4.1-36.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050802003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050802005" version="502" comment="xloadimage is earlier than 0:4.1-36.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050802005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050803002" version="502" comment="lynx is earlier than 0:2.8.5-11.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050803002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050803003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050803003" version="502" comment="lynx is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050803002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050803005" version="502" comment="lynx is earlier than 0:2.8.5-18.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050803002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050803005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050805002" version="502" comment="pam is earlier than 0:0.77-66.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050805002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050805003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050805003" version="502" comment="pam is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050805002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050805004" version="502" comment="pam-devel is earlier than 0:0.77-66.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050805003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050805003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050805005" version="502" comment="pam-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050805003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050807002" version="501" comment="curl is earlier than 0:7.10.6-7.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050807003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050807004" version="501" comment="curl-devel is earlier than 0:7.10.6-7.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050807003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050807007" version="501" comment="curl is earlier than 0:7.12.1-6.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050807005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050807008" version="501" comment="curl-devel is earlier than 0:7.12.1-6.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050807005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808002" version="503" comment="kernel is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808004" version="503" comment="kernel-devel is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808006" version="503" comment="kernel-doc is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808008" version="503" comment="kernel-smp is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808010" version="503" comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808012" version="503" comment="kernel-hugemem is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050043010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050808014" version="503" comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.1.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050092008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050808003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050809002" version="502" comment="ethereal is earlier than 0:0.10.13-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050809003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050809004" version="502" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050809003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050809007" version="502" comment="ethereal is earlier than 0:0.10.13-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050809005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050809008" version="502" comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050809005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050810002" version="502" comment="gdk-pixbuf is earlier than 1:0.22.0-13.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050810003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050810004" version="502" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-13.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050810003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050810006" version="502" comment="gdk-pixbuf-gnome is earlier than 1:0.22.0-13.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050810003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050810009" version="502" comment="gdk-pixbuf is earlier than 1:0.22.0-17.el4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050810005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050810010" version="502" comment="gdk-pixbuf-devel is earlier than 1:0.22.0-17.el4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050810005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050811002" version="502" comment="gtk2 is earlier than 0:2.2.4-19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050811003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050811004" version="502" comment="gtk2-devel is earlier than 0:2.2.4-19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050811003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050811007" version="502" comment="gtk2 is earlier than 0:2.4.13-18" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050811005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050811008" version="502" comment="gtk2-devel is earlier than 0:2.4.13-18" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050811005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050812002" version="502" comment="wget is earlier than 0:1.10.2-0.30E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050771002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050812003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050812005" version="502" comment="wget is earlier than 0:1.10.2-0.40E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050771002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050812005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050825002" version="502" comment="lm_sensors is earlier than 0:2.8.7-2.40.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050825002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050825003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050825003" version="502" comment="lm_sensors is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050825002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050825004" version="502" comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050825003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050825003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050825005" version="502" comment="lm_sensors-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050825003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828002" version="502" comment="libungif is earlier than 0:4.1.0-15.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828003" version="502" comment="libungif is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828004" version="502" comment="libungif-devel is earlier than 0:4.1.0-15.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828005" version="502" comment="libungif-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828006" version="502" comment="libungif-progs is earlier than 0:4.1.0-15.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828007" version="502" comment="libungif-progs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828009" version="502" comment="libungif is earlier than 0:4.1.3-1.el4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828010" version="502" comment="libungif-devel is earlier than 0:4.1.3-1.el4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050828011" version="502" comment="libungif-progs is earlier than 0:4.1.3-1.el4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050828004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050828005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050830002" version="501" comment="openssl096b is earlier than 0:0.9.6b-16.42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050830003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050830005" version="501" comment="openssl096b is earlier than 0:0.9.6b-22.42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050830005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831002" version="502" comment="php is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831004" version="502" comment="php-devel is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831006" version="502" comment="php-imap is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831008" version="502" comment="php-ldap is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831010" version="502" comment="php-mysql is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831012" version="502" comment="php-pgsql is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831014" version="502" comment="php-odbc is earlier than 0:4.3.2-26.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831017" version="502" comment="php is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831018" version="502" comment="php-devel is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831019" version="502" comment="php-pear is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831021" version="502" comment="php-imap is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831022" version="502" comment="php-ldap is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831023" version="502" comment="php-mysql is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831024" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831025" version="502" comment="php-odbc is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831026" version="502" comment="php-snmp is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831028" version="502" comment="php-domxml is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831030" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831032" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831034" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050831036" version="502" comment="php-gd is earlier than 0:4.3.9-3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050032015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050831005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050839002" version="502" comment="lynx is earlier than 0:2.8.5-11.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050803002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050839003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050839005" version="502" comment="lynx is earlier than 0:2.8.5-18.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050803002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050839005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050840002" version="503" comment="xpdf is earlier than 1:2.02-9.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050840003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050840005" version="503" comment="xpdf is earlier than 1:3.00-11.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050840005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050843002" version="502" comment="netpbm is earlier than 0:9.24-11.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050843003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050843004" version="502" comment="netpbm-devel is earlier than 0:9.24-11.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050843003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050843006" version="502" comment="netpbm-progs is earlier than 0:9.24-11.30.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050743004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050843003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050848002" version="503" comment="libc-client is earlier than 0:2002e-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050848002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050848003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050848003" version="503" comment="libc-client is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050848002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050848004" version="503" comment="libc-client-devel is earlier than 0:2002e-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050848003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050848003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050848005" version="503" comment="libc-client-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050848003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050850002" version="502" comment="imap is earlier than 1:2002d-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050850003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050850004" version="502" comment="imap-devel is earlier than 1:2002d-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050850003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050850006" version="502" comment="imap-utils is earlier than 1:2002d-12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050128004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050850003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050864002" version="502" comment="udev is earlier than 0:039-10.10.EL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050864002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050864003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050864003" version="502" comment="udev is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050864002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050009001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050867002" version="502" comment="gpdf is earlier than 0:2.8.2-7.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050057002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050867003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050868002" version="502" comment="kdegraphics is earlier than 7:3.3.1-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050868003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050868004" version="502" comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050021003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050868003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050875002" version="502" comment="curl is earlier than 0:7.12.1-8.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050875003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050875004" version="502" comment="curl-devel is earlier than 0:7.12.1-8.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050340003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050875003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878002" version="502" comment="cups is earlier than 1:1.1.17-13.3.34" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.34" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.34" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878009" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878010" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050878011" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050878005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050880002" version="502" comment="perl is earlier than 3:5.8.5-24.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050880003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050880004" version="502" comment="perl-suidperl is earlier than 3:5.8.5-24.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050880003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050881002" version="502" comment="perl is earlier than 2:5.8.0-90.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050881003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050881004" version="502" comment="perl-CPAN is earlier than 2:1.61-90.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050881004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050881006" version="502" comment="perl-CGI is earlier than 2:2.89-90.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050881005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050881008" version="502" comment="perl-DB_File is earlier than 2:1.806-90.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050105005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050881006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20050881010" version="502" comment="perl-suidperl is earlier than 2:5.8.0-90.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20050103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20050881003" />
</rpminfo_test>
</tests>

<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050009001" version="502">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050009002" version="502">
  <name>kdelibs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050009003" version="502">
  <name>kdelibs-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050009004" version="502">
  <name>kdebase</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050009005" version="502">
  <name>kdebase-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050010002" version="502">
  <name>vim</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050010003" version="502">
  <name>vim-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050010004" version="502">
  <name>vim-minimal</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050010005" version="502">
  <name>vim-enhanced</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050010006" version="502">
  <name>vim-X11</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050011002" version="502">
  <name>ethereal</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050011003" version="502">
  <name>ethereal-gnome</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050012002" version="502">
  <name>krb5</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050012003" version="502">
  <name>krb5-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050012004" version="502">
  <name>krb5-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050012005" version="502">
  <name>krb5-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050012006" version="502">
  <name>krb5-workstation</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050013002" version="502">
  <name>cups</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050013003" version="502">
  <name>cups-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050013004" version="502">
  <name>cups-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050018002" version="502">
  <name>xpdf</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050019002" version="502">
  <name>libtiff</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050019003" version="502">
  <name>libtiff-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050021002" version="502">
  <name>kdegraphics</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050021003" version="502">
  <name>kdegraphics-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050025002" version="502">
  <name>exim</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050025003" version="502">
  <name>exim-mon</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050025004" version="502">
  <name>exim-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050025005" version="502">
  <name>exim-sa</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026002" version="502">
  <name>tetex</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026003" version="502">
  <name>tetex-latex</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026004" version="502">
  <name>tetex-xdvi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026005" version="502">
  <name>tetex-dvips</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026006" version="502">
  <name>tetex-afm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026007" version="502">
  <name>tetex-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050026008" version="502">
  <name>tetex-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032002" version="502">
  <name>php</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032003" version="502">
  <name>php-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032004" version="502">
  <name>php-pear</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032005" version="502">
  <name>php-imap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032006" version="502">
  <name>php-ldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032007" version="502">
  <name>php-mysql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032008" version="502">
  <name>php-pgsql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032009" version="502">
  <name>php-odbc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032010" version="502">
  <name>php-snmp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032011" version="502">
  <name>php-domxml</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032012" version="502">
  <name>php-xmlrpc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032013" version="502">
  <name>php-mbstring</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032014" version="502">
  <name>php-ncurses</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050032015" version="502">
  <name>php-gd</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050033002" version="502">
  <name>alsa-lib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050033003" version="502">
  <name>alsa-lib-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038002" version="504">
  <name>mozilla</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038003" version="504">
  <name>mozilla-nspr</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038004" version="504">
  <name>mozilla-nspr-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038005" version="504">
  <name>mozilla-nss</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038006" version="504">
  <name>mozilla-nss-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038007" version="504">
  <name>mozilla-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038008" version="504">
  <name>mozilla-mail</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038009" version="504">
  <name>mozilla-chat</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038010" version="504">
  <name>mozilla-js-debugger</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050038011" version="504">
  <name>mozilla-dom-inspector</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050039002" version="502">
  <name>enscript</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043002" version="502">
  <name>kernel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043003" version="502">
  <name>kernel-source</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043004" version="502">
  <name>kernel-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043005" version="502">
  <name>kernel-unsupported</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043006" version="502">
  <name>kernel-smp-unsupported</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043007" version="502">
  <name>kernel-smp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043008" version="502">
  <name>kernel-BOOT</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043009" version="502">
  <name>kernel-hugemem-unsupported</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050043010" version="502">
  <name>kernel-hugemem</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050057002" version="502">
  <name>gpdf</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050060002" version="502">
  <name>squid</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050068002" version="502">
  <name>less</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050069002" version="502">
  <name>perl-DBI</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050070002" version="502">
  <name>ImageMagick</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050070003" version="502">
  <name>ImageMagick-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050070004" version="502">
  <name>ImageMagick-perl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050070005" version="502">
  <name>ImageMagick-c++</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050070006" version="502">
  <name>ImageMagick-c++-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050073002" version="502">
  <name>cpio</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050074002" version="502">
  <name>rsh</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050074003" version="502">
  <name>rsh-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050081002" version="503">
  <name>ghostscript</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050081003" version="503">
  <name>ghostscript-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050081004" version="503">
  <name>hpijs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050090002" version="502">
  <name>htdig</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050090003" version="502">
  <name>htdig-web</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050092003" version="502">
  <name>kernel-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050092006" version="502">
  <name>kernel-smp-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050092008" version="502">
  <name>kernel-hugemem-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050094002" version="502">
  <name>thunderbird</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050099002" version="502">
  <name>squirrelmail</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050100002" version="502">
  <name>mod_python</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050102002" version="502">
  <name>dbus</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050102003" version="502">
  <name>dbus-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050102004" version="502">
  <name>dbus-glib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050102005" version="502">
  <name>dbus-x11</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050102006" version="502">
  <name>dbus-python</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050103002" version="502">
  <name>perl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050103003" version="502">
  <name>perl-suidperl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050105003" version="502">
  <name>perl-CPAN</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050105004" version="502">
  <name>perl-CGI</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050105005" version="502">
  <name>perl-DB_File</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050106002" version="502">
  <name>openssh</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050106003" version="502">
  <name>openssh-clients</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050106004" version="502">
  <name>openssh-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050106005" version="502">
  <name>openssh-askpass</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050106006" version="502">
  <name>openssh-askpass-gnome</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050108002" version="502">
  <name>python</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050108003" version="502">
  <name>python-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050108004" version="502">
  <name>python-tools</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050108005" version="502">
  <name>python-docs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050108006" version="502">
  <name>tkinter</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050110002" version="502">
  <name>emacs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050110003" version="502">
  <name>emacs-nox</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050110004" version="502">
  <name>emacs-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050110005" version="502">
  <name>emacs-el</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050110006" version="502">
  <name>emacs-leim</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050128002" version="502">
  <name>imap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050128003" version="502">
  <name>imap-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050128004" version="502">
  <name>imap-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050133002" version="502">
  <name>xemacs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050133003" version="502">
  <name>xemacs-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050133004" version="502">
  <name>xemacs-nox</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050133005" version="502">
  <name>xemacs-el</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050133006" version="502">
  <name>xemacs-info</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050136002" version="503">
  <name>mailman</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138002" version="502">
  <name>postgresql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138003" version="502">
  <name>postgresql-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138004" version="502">
  <name>postgresql-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138005" version="502">
  <name>postgresql-docs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138006" version="502">
  <name>postgresql-contrib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138007" version="502">
  <name>postgresql-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138008" version="502">
  <name>postgresql-pl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138009" version="502">
  <name>postgresql-tcl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138010" version="502">
  <name>postgresql-python</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138011" version="502">
  <name>postgresql-jdbc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050138012" version="502">
  <name>postgresql-test</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141002" version="502">
  <name>rh-postgresql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141003" version="502">
  <name>rh-postgresql-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141004" version="502">
  <name>rh-postgresql-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141005" version="502">
  <name>rh-postgresql-docs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141006" version="502">
  <name>rh-postgresql-contrib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141007" version="502">
  <name>rh-postgresql-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141008" version="502">
  <name>rh-postgresql-pl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141009" version="502">
  <name>rh-postgresql-tcl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141010" version="502">
  <name>rh-postgresql-python</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141011" version="502">
  <name>rh-postgresql-jdbc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050141012" version="502">
  <name>rh-postgresql-test</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050152002" version="502">
  <name>postfix</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050152003" version="502">
  <name>postfix-pflogsumm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050175002" version="502">
  <name>kdenetwork</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050175003" version="502">
  <name>kdenetwork-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050176002" version="502">
  <name>firefox</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198002" version="502">
  <name>xorg-x11</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198003" version="502">
  <name>xorg-x11-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198004" version="502">
  <name>xorg-x11-deprecated-libs-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198005" version="502">
  <name>xorg-x11-font-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198006" version="502">
  <name>xorg-x11-xfs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198007" version="502">
  <name>xorg-x11-twm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198008" version="502">
  <name>xorg-x11-xdm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198009" version="502">
  <name>xorg-x11-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198010" version="502">
  <name>xorg-x11-deprecated-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198011" version="502">
  <name>xorg-x11-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198012" version="502">
  <name>xorg-x11-Xdmx</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198013" version="502">
  <name>xorg-x11-Xnest</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198014" version="502">
  <name>xorg-x11-tools</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198015" version="502">
  <name>xorg-x11-xauth</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198016" version="502">
  <name>xorg-x11-Mesa-libGL</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198017" version="502">
  <name>xorg-x11-Mesa-libGLU</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198018" version="502">
  <name>xorg-x11-Xvfb</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198019" version="502">
  <name>xorg-x11-sdk</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198020" version="502">
  <name>fonts-xorg</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198021" version="502">
  <name>fonts-xorg-base</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198022" version="502">
  <name>fonts-xorg-truetype</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198023" version="502">
  <name>fonts-xorg-syriac</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198024" version="502">
  <name>fonts-xorg-75dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198025" version="502">
  <name>fonts-xorg-100dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198026" version="502">
  <name>fonts-xorg-ISO8859-2-75dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198027" version="502">
  <name>fonts-xorg-ISO8859-2-100dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198028" version="502">
  <name>fonts-xorg-ISO8859-9-75dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198029" version="502">
  <name>fonts-xorg-ISO8859-9-100dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198030" version="502">
  <name>fonts-xorg-ISO8859-14-75dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198031" version="502">
  <name>fonts-xorg-ISO8859-14-100dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198032" version="502">
  <name>fonts-xorg-ISO8859-15-75dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198033" version="502">
  <name>fonts-xorg-ISO8859-15-100dpi</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050198034" version="502">
  <name>fonts-xorg-cyrillic</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050215002" version="502">
  <name>gaim</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050232002" version="502">
  <name>ipsec-tools</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050238002" version="502">
  <name>evolution</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050238003" version="502">
  <name>evolution-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256002" version="502">
  <name>glibc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256003" version="502">
  <name>glibc-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256004" version="502">
  <name>glibc-headers</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256005" version="502">
  <name>nptl-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256006" version="502">
  <name>glibc-profile</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256007" version="502">
  <name>glibc-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256008" version="502">
  <name>nscd</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256009" version="502">
  <name>glibc-debug</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050256010" version="502">
  <name>glibc-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050271002" version="502">
  <name>HelixPlayer</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050300002" version="502">
  <name>libexif</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050300003" version="502">
  <name>libexif-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050327002" version="502">
  <name>telnet</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050327003" version="502">
  <name>telnet-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331002" version="502">
  <name>XFree86</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331003" version="502">
  <name>XFree86-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331004" version="502">
  <name>XFree86-font-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331005" version="502">
  <name>XFree86-xfs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331006" version="502">
  <name>XFree86-twm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331007" version="502">
  <name>XFree86-xdm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331008" version="502">
  <name>XFree86-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331009" version="502">
  <name>XFree86-libs-data</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331010" version="502">
  <name>XFree86-base-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331011" version="502">
  <name>XFree86-truetype-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331012" version="502">
  <name>XFree86-syriac-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331013" version="502">
  <name>XFree86-75dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331014" version="502">
  <name>XFree86-100dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331015" version="502">
  <name>XFree86-ISO8859-2-75dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331016" version="502">
  <name>XFree86-ISO8859-2-100dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331017" version="502">
  <name>XFree86-ISO8859-9-75dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331018" version="502">
  <name>XFree86-ISO8859-9-100dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331019" version="502">
  <name>XFree86-ISO8859-14-75dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331020" version="502">
  <name>XFree86-ISO8859-14-100dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331021" version="502">
  <name>XFree86-ISO8859-15-75dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331022" version="502">
  <name>XFree86-ISO8859-15-100dpi-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331023" version="502">
  <name>XFree86-cyrillic-fonts</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331024" version="502">
  <name>XFree86-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331025" version="502">
  <name>XFree86-Xnest</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331026" version="502">
  <name>XFree86-Xvfb</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331027" version="502">
  <name>XFree86-tools</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331028" version="502">
  <name>XFree86-xauth</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331029" version="502">
  <name>XFree86-Mesa-libGL</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331030" version="502">
  <name>XFree86-Mesa-libGLU</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050331031" version="502">
  <name>XFree86-sdk</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050332002" version="502">
  <name>xloadimage</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050334002" version="502">
  <name>mysql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050334003" version="502">
  <name>mysql-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050334004" version="502">
  <name>mysql-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050334005" version="502">
  <name>mysql-bench</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050335012" version="503">
  <name>devhelp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050335013" version="503">
  <name>devhelp-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050340002" version="502">
  <name>curl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050340003" version="502">
  <name>curl-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050343002" version="502">
  <name>gdk-pixbuf</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050343003" version="502">
  <name>gdk-pixbuf-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050343004" version="502">
  <name>gdk-pixbuf-gnome</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050344002" version="502">
  <name>gtk2</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050344003" version="502">
  <name>gtk2-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050345002" version="503">
  <name>slocate</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050357002" version="502">
  <name>gzip</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050361002" version="502">
  <name>vixie-cron</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050373002" version="502">
  <name>net-snmp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050373003" version="502">
  <name>net-snmp-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050373004" version="502">
  <name>net-snmp-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050373005" version="502">
  <name>net-snmp-perl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050373006" version="502">
  <name>net-snmp-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050375002" version="502">
  <name>openoffice.org</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050375003" version="502">
  <name>openoffice.org-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050375004" version="502">
  <name>openoffice.org-i18n</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050375005" version="502">
  <name>openoffice.org-kde</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050377002" version="502">
  <name>sharutils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050381002" version="502">
  <name>nasm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050381003" version="502">
  <name>nasm-doc</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050381004" version="502">
  <name>nasm-rdoff</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050387002" version="502">
  <name>cvs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408002" version="502">
  <name>cyrus-imapd</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408003" version="502">
  <name>cyrus-imapd-murder</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408004" version="502">
  <name>cyrus-imapd-nntp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408005" version="502">
  <name>cyrus-imapd-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408006" version="502">
  <name>perl-Cyrus</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050408007" version="502">
  <name>cyrus-imapd-utils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050410002" version="502">
  <name>gftp</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050412002" version="502">
  <name>openmotif21</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050412003" version="502">
  <name>openmotif</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050412004" version="502">
  <name>openmotif-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050417002" version="503">
  <name>tcpdump</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050417003" version="503">
  <name>libpcap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050417004" version="503">
  <name>arpwatch</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050430002" version="502">
  <name>gnutls</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050430003" version="502">
  <name>gnutls-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050474002" version="503">
  <name>bzip2</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050474003" version="503">
  <name>bzip2-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050474004" version="503">
  <name>bzip2-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050476002" version="502">
  <name>openssl096b</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050476003" version="502">
  <name>openssl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050476004" version="502">
  <name>openssl-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050476005" version="502">
  <name>openssl-perl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050498002" version="502">
  <name>spamassassin</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050499002" version="502">
  <name>gedit</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050499003" version="502">
  <name>gedit-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050502002" version="502">
  <name>sysreport</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050506002" version="502">
  <name>mikmod</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050506003" version="502">
  <name>mikmod-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050524002" version="502">
  <name>freeradius</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050524003" version="502">
  <name>freeradius-mysql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050524004" version="502">
  <name>freeradius-postgresql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050524005" version="502">
  <name>freeradius-unixODBC</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050535002" version="505">
  <name>sudo</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543002" version="502">
  <name>ruby</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543003" version="502">
  <name>ruby-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543004" version="502">
  <name>ruby-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543005" version="502">
  <name>ruby-tcltk</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543006" version="502">
  <name>irb</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543007" version="502">
  <name>ruby-docs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050543008" version="502">
  <name>ruby-mode</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050569002" version="502">
  <name>zlib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050569003" version="502">
  <name>zlib-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050582002" version="502">
  <name>httpd</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050582003" version="502">
  <name>httpd-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050582004" version="502">
  <name>mod_ssl</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050582005" version="502">
  <name>httpd-manual</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050582006" version="502">
  <name>httpd-suexec</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050639004" version="502">
  <name>kdenetwork-nowlistening</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050640002" version="502">
  <name>fetchmail</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050659002" version="502">
  <name>binutils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050709002" version="502">
  <name>gdb</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050743002" version="502">
  <name>netpbm</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050743003" version="502">
  <name>netpbm-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050743004" version="502">
  <name>netpbm-progs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050751002" version="502">
  <name>openldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050751003" version="502">
  <name>openldap-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050751004" version="502">
  <name>openldap-servers</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050751005" version="502">
  <name>openldap-clients</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050751006" version="502">
  <name>nss_ldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050761002" version="503">
  <name>pcre</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050761003" version="503">
  <name>pcre-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050767005" version="502">
  <name>openldap-servers-sql</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050767007" version="502">
  <name>compat-openldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050771002" version="502">
  <name>wget</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050782002" version="502">
  <name>util-linux</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050782003" version="502">
  <name>mount</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050782004" version="502">
  <name>losetup</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050803002" version="502">
  <name>lynx</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050805002" version="502">
  <name>pam</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050805003" version="502">
  <name>pam-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050825002" version="502">
  <name>lm_sensors</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050825003" version="502">
  <name>lm_sensors-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050828002" version="502">
  <name>libungif</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050828003" version="502">
  <name>libungif-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050828004" version="502">
  <name>libungif-progs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050848002" version="503">
  <name>libc-client</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050848003" version="503">
  <name>libc-client-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:obj:20050864002" version="502">
  <name>udev</name>
</rpminfo_object>
</objects>

<states>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050009001" version="502">
  <signature_keyid operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050009002" version="502">
  <version operation="pattern match">^3[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050009003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.1.3-6.9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050009004" version="502">
  <evr datatype="evr_string" operation="less than">6:3.1.3-5.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050010003" version="502">
  <evr datatype="evr_string" operation="less than">1:6.3.046-0.30E.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050011003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.9-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050012003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.2.7-38</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050013003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.22</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050018003" version="502">
  <evr datatype="evr_string" operation="less than">1:2.02-9.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050019003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.5.7-22.el3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050021003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.1.3-3.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050025002" version="502">
  <version operation="pattern match">^4[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050025003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.43-1.RHEL4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050026003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.2-22.EL4.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050032003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.9-3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050033003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.6-5.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050034003" version="502">
  <evr datatype="evr_string" operation="less than">1:3.00-11.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050035003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.6.1-8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050036003" version="502">
  <evr datatype="evr_string" operation="less than">1:6.3.046-0.40E.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050037003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.9-1.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050038003" version="504">
  <evr datatype="evr_string" operation="less than">37:1.4.3-3.0.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050039003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.6.1-24.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050040003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.6.1-28.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050043003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.21-27.0.2.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050045003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.4-10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050049003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.24</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050053003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.22-0.rc1.9.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050057003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.2-4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050059003" version="502">
  <evr datatype="evr_string" operation="less than">1:2.02-9.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050060003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE6-3.4E.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050061003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-6.3E.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050065003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.3.1-3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050066003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.3.1-3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050068003" version="502">
  <evr datatype="evr_string" operation="less than">0:378-12</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050069003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.32-9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050070003" version="502">
  <evr datatype="evr_string" operation="less than">0:5.5.6-13</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050071003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.0.7.1-6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050072003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.40-8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050073003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.5-7.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050074003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.17-17.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050080003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.5-3e.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050081003" version="503">
  <evr datatype="evr_string" operation="less than">0:7.05-32.1.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050081004" version="503">
  <evr datatype="evr_string" operation="less than">0:1.3-32.1.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050090003" version="502">
  <evr datatype="evr_string" operation="less than">3:3.2.0b6-3.40.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050092003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.6.9-5.0.3.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050094003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0-1.1.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050099003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.4.3a-9.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050100003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.1.3-5.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050102003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.22-12.EL.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050103003" version="502">
  <evr datatype="evr_string" operation="less than">3:5.8.5-12.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050103004" version="502">
  <evr datatype="evr_string" operation="less than">3:5.8.5-12.1.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050104003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.0.3-5.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050105003" version="502">
  <evr datatype="evr_string" operation="less than">2:5.8.0-89.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050105004" version="502">
  <evr datatype="evr_string" operation="less than">2:1.61-89.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050105005" version="502">
  <evr datatype="evr_string" operation="less than">2:2.81-89.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050105006" version="502">
  <evr datatype="evr_string" operation="less than">2:1.804-89.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050106003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.6.1p2-33.30.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050108003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.3.4-14.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050109003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.3-6.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050110003" version="502">
  <evr datatype="evr_string" operation="less than">0:21.3-19.EL.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050112003" version="502">
  <evr datatype="evr_string" operation="less than">0:21.3-4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050122003" version="502">
  <evr datatype="evr_string" operation="less than">1:6.3.046-0.30E.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050128003" version="502">
  <evr datatype="evr_string" operation="less than">1:2002d-11</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050132003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.27</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050133003" version="502">
  <evr datatype="evr_string" operation="less than">0:21.4.15-10.EL.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050134003" version="502">
  <evr datatype="evr_string" operation="less than">0:21.4.13-8.ent.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050135003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.4.3a-9.EL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050136003" version="503">
  <evr datatype="evr_string" operation="less than">3:2.1.5-24.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050137003" version="502">
  <evr datatype="evr_string" operation="less than">3:2.1.5-31.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050138003" version="502">
  <evr datatype="evr_string" operation="less than">0:7.4.7-2.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050141003" version="502">
  <evr datatype="evr_string" operation="less than">0:7.3.9-2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050152003" version="502">
  <evr datatype="evr_string" operation="less than">2:2.1.5-4.2.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050165003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.17-25.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050173003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-6.3E.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050175003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.1.3-1.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050176003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.1-1.4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050198003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.8.2-1.EL.13.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050198004" version="502">
  <evr datatype="evr_string" operation="less than">0:6.8.1.1-1.EL.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050201003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE6-3.4E.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050213003" version="502">
  <evr datatype="evr_string" operation="less than">1:2.02-9.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050215003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.4-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050215005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.4-1.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050232003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.2.5-0.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050232005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.3.3-6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050235003" version="502">
  <evr datatype="evr_string" operation="less than">3:2.1.5-25.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050235005" version="502">
  <evr datatype="evr_string" operation="less than">3:2.1.5-33.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050238003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.4.5-14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050256003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.3.2-95.33</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050267003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.4.5-16</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050267005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.2-16.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050271003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.0.3-1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050277003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.3-19.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050293003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.21-27.0.4.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050294003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.21-32.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050300003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.5.12-5.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050306003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.10-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050306005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.10-1.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050307003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.1.3-6.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050320003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.0.7.1-10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050323003" version="503">
  <evr datatype="evr_string" operation="less than">37:1.4.4-1.3.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050325003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.3.1-3.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050327003" version="502">
  <evr datatype="evr_string" operation="less than">1:0.17-26.EL3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050327005" version="502">
  <evr datatype="evr_string" operation="less than">1:0.17-31.EL4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050330003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.2.7-42</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050330005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.4-12</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050331003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.0-81.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050332003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1-34.RHEL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050332005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1-34.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050334003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.23.58-15.RHEL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050334005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1.10a-1.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050335003" version="503">
  <evr datatype="evr_string" operation="less than">37:1.7.6-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050335004" version="503">
  <evr datatype="evr_string" operation="less than">0:0.9.2-2.4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050335005" version="503">
  <evr datatype="evr_string" operation="less than">0:2.0.2-14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050336003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.2-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050340003" version="502">
  <evr datatype="evr_string" operation="less than">0:7.10.6-6.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050340005" version="502">
  <evr datatype="evr_string" operation="less than">0:7.12.1-5.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050343003" version="502">
  <evr datatype="evr_string" operation="less than">1:0.22.0-12.el3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050343005" version="502">
  <evr datatype="evr_string" operation="less than">1:0.22.0-16.el4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050344003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.4-15</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050344005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.13-14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050345003" version="503">
  <evr datatype="evr_string" operation="less than">0:2.7-3.RHEL3.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050346003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.7-13.el4.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050354003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.7-67.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050357003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.3-12.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050357005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.3-15.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050358003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.43-1.RHEL4.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050361003" version="502">
  <evr datatype="evr_string" operation="less than">4:4.1-36.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050365003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.2.1-4.el3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050365005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.2.1-4.el4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050366003" version="503">
  <evr datatype="evr_string" operation="less than">0:2.6.9-5.0.5.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050373003" version="502">
  <evr datatype="evr_string" operation="less than">0:5.0.9-2.30E.19</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050375003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.1.2-24.2.0.EL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050375005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.1.2-24.6.0.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050377003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.2.1-16.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050377005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.2.1-22.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050378003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.5-4.RHEL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050378005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.5-8.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050381003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.98.35-3.EL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050381005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.98.38-3.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050383003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.3-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050384003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.7-1.1.3.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050386003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.7-1.4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050386004" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.2-2.4.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050387003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.11.2-27</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050387005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.11.17-7.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050392003" version="504">
  <evr datatype="evr_string" operation="less than">1:1.0.4-1.1.EL4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050393003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.3.1-3.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050395003" version="502">
  <evr datatype="evr_string" operation="less than">0:5.1.2-11.EL4.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050396003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.8.2-1.EL.13.16</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050397003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.2-16</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050405003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.2-23.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050406003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.9-3.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050408003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.12-3.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050410003" version="502">
  <evr datatype="evr_string" operation="less than">1:2.0.14-4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050410005" version="502">
  <evr datatype="evr_string" operation="less than">1:2.0.17-5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050412003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.1.30-9.RHEL3.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050412004" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.3-5.RHEL3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050412006" version="502">
  <evr datatype="evr_string" operation="less than">0:2.1.30-11.RHEL4.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050412007" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.3-9.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050413003" version="502">
  <evr datatype="evr_string" operation="less than">0:5.5.6-14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050413005" version="502">
  <evr datatype="evr_string" operation="less than">0:6.0.7.1-11</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050415003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-6.3E.13</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050415005" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE6-3.4E.9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050417003" version="503">
  <evr datatype="evr_string" operation="less than">14:3.8.2-9.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050417004" version="503">
  <evr datatype="evr_string" operation="less than">14:0.8.3-9.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050417005" version="503">
  <evr datatype="evr_string" operation="less than">14:2.1a13-9.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050420003" version="503">
  <evr datatype="evr_string" operation="less than">0:2.6.9-11.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050421003" version="503">
  <evr datatype="evr_string" operation="less than">14:3.7.2-7.E3.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050421004" version="503">
  <evr datatype="evr_string" operation="less than">14:0.7.2-7.E3.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050421005" version="503">
  <evr datatype="evr_string" operation="less than">14:2.1a11-7.E3.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050427003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.11-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050427005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.11-1.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050429003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.2.1-6.el3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050429005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.2.1-6.el4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050430003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.20-3.2.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050433003" version="502">
  <evr datatype="evr_string" operation="less than">0:7.3.10-1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050433005" version="502">
  <evr datatype="evr_string" operation="less than">0:7.4.8-1.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050434003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.4-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050435003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.8-1.1.3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050435005" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.8-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050435006" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.2-2.4.5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050472003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.21-32.0.1.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050474003" version="503">
  <evr datatype="evr_string" operation="less than">0:1.0.2-11.EL3.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050474005" version="503">
  <evr datatype="evr_string" operation="less than">0:1.0.2-13.EL4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050476003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-16.22.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050476004" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.7a-33.15</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050476006" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-22.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050476007" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.7a-43.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050480003" version="502">
  <evr datatype="evr_string" operation="less than">0:5.5.6-15</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050480005" version="502">
  <evr datatype="evr_string" operation="less than">0:6.0.7.1-12</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050498003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.0.4-1.el4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050499003" version="502">
  <evr datatype="evr_string" operation="less than">1:2.2.2-4.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050499005" version="502">
  <evr datatype="evr_string" operation="less than">1:2.8.1-4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050501003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.0-95.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050502003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.7.2-6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050502005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.15-2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050504003" version="501">
  <evr datatype="evr_string" operation="less than">1:0.17-26.EL3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050504005" version="501">
  <evr datatype="evr_string" operation="less than">1:0.17-31.EL4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050505003" version="502">
  <evr datatype="evr_string" operation="less than">14:3.8.2-10.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050505004" version="502">
  <evr datatype="evr_string" operation="less than">14:0.8.3-10.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050505005" version="502">
  <evr datatype="evr_string" operation="less than">14:2.1a13-10.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050506003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.1.6-22.EL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050506005" version="502">
  <evr datatype="evr_string" operation="less than">0:3.1.6-32.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050514003" version="504">
  <evr datatype="evr_string" operation="less than">0:2.6.9-22.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050517003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.0.5-0.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050518003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.3.1-0.el3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050518005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.3.1-0.el4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050524003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.1-1.1.RHEL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050524005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.1-3.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050527003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.9p1-8.RHEL4.9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050535003" version="505">
  <evr datatype="evr_string" operation="less than">0:1.6.7p5-1.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050535005" version="505">
  <evr datatype="evr_string" operation="less than">0:1.6.7p5-30.1.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050543003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.8.1-7.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050550003" version="502">
  <evr datatype="evr_string" operation="less than">0:3.6.1p2-33.30.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050562003" version="503">
  <evr datatype="evr_string" operation="less than">0:1.2.7-47</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050564003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.2-24.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050564005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.9-3.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050567003" version="503">
  <evr datatype="evr_string" operation="less than">0:1.3.4-17</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050569003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.2.1.2-1.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050571003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.29</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050582003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.46-46.2.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050582005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.52-12.1.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050584003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.2.1.2-1.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050586003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.6-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050587003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.10-1.1.3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050587005" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.10-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050587006" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.2-2.4.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050595003" version="503">
  <evr datatype="evr_string" operation="less than">0:1.4.3a-11.EL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050595005" version="503">
  <evr datatype="evr_string" operation="less than">0:1.4.3a-12.EL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050598003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.7.2-9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050598005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.3.15-5</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050608003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.46-46.3.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050608005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.52-12.2.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050612003" version="502">
  <evr datatype="evr_string" operation="less than">6:3.3.1-3.11</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050627003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.3.1-0.el3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050627005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.3.1-0.el4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050639003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.3.1-2.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050640003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.2.0-3.el3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050640005" version="502">
  <evr datatype="evr_string" operation="less than">0:6.2.5-6.el4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050659003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.14.90.0.4-39</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050663003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.21-37.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050670003" version="502">
  <evr datatype="evr_string" operation="less than">1:3.00-11.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050671003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.3.1-3.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050673003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.15.92.0.2-15</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050674003" version="502">
  <evr datatype="evr_string" operation="less than">3:5.8.5-16.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050685003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1.12-3.RHEL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050687003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.12-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050687005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.12-1.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050706003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.31</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050706005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.22-0.rc1.9.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050708003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.2-4.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050709003" version="502">
  <evr datatype="evr_string" operation="less than">0:6.3.0.0-1.63</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050743003" version="502">
  <evr datatype="evr_string" operation="less than">0:9.24-11.30.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050743005" version="502">
  <evr datatype="evr_string" operation="less than">0:10.25-2.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050745003" version="502">
  <evr datatype="evr_string" operation="less than">1:6.3.046-0.30E.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050745005" version="502">
  <evr datatype="evr_string" operation="less than">1:6.3.046-0.40E.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050748003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.2-25.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050748005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.9-3.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050751003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.0.27-20</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050751004" version="502">
  <evr datatype="evr_string" operation="less than">0:207-17</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050756003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.11.2-28</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050756005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.11.17-8.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050761003" version="503">
  <evr datatype="evr_string" operation="less than">0:3.9-10.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050761005" version="503">
  <evr datatype="evr_string" operation="less than">0:4.5-3.2.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050766003" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-6.3E.14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050766005" version="502">
  <evr datatype="evr_string" operation="less than">7:2.5.STABLE6-3.4E.11</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050767003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.13-4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050767004" version="502">
  <evr datatype="evr_string" operation="less than">0:2.1.30-4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050767005" version="502">
  <evr datatype="evr_string" operation="less than">0:226-10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050768003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.6-1.4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050769003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.10-1.1.3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050769005" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.10-1.4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050771003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.10.1-1.30E.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050771005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.10.1-2.4E.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050772003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.22-0.rc1.9.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050782003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.11y-31.11</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050782005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.12a-16.EL4.12</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050785003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.0.7-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050788003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.0.6-0.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050789003" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.12-1.1.3.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050789005" version="502">
  <evr datatype="evr_string" operation="less than">37:1.7.12-1.4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050789006" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.2-2.4.7</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050793003" version="502">
  <evr datatype="evr_string" operation="less than">0:10.25-2.EL4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050799003" version="503">
  <evr datatype="evr_string" operation="less than">0:1.6.8-9.EL3.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050799005" version="503">
  <evr datatype="evr_string" operation="less than">0:1.8.1-7.EL4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050800003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-16.22.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050800004" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.7a-33.17</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050800006" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-22.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050800007" version="502">
  <evr datatype="evr_string" operation="less than">0:0.9.7a-43.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050802003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1-36.RHEL3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050802005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1-36.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050803003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.5-11.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050803005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.5-18.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050805003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.77-66.13</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050807003" version="501">
  <evr datatype="evr_string" operation="less than">0:7.10.6-7.rhel3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050807005" version="501">
  <evr datatype="evr_string" operation="less than">0:7.12.1-6.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050808003" version="503">
  <evr datatype="evr_string" operation="less than">0:2.6.9-22.0.1.EL</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050809003" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.13-1.EL3.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050809005" version="502">
  <evr datatype="evr_string" operation="less than">0:0.10.13-1.EL4.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050810003" version="502">
  <evr datatype="evr_string" operation="less than">1:0.22.0-13.el3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050810005" version="502">
  <evr datatype="evr_string" operation="less than">1:0.22.0-17.el4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050811003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.2.4-19</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050811005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.4.13-18</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050812003" version="502">
  <evr datatype="evr_string" operation="less than">0:1.10.2-0.30E</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050812005" version="502">
  <evr datatype="evr_string" operation="less than">0:1.10.2-0.40E</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050825003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.7-2.40.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050828003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1.0-15.el3.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050828005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.1.3-1.el4.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050830003" version="501">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-16.42</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050830005" version="501">
  <evr datatype="evr_string" operation="less than">0:0.9.6b-22.42</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050831003" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.2-26.ent</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050831005" version="502">
  <evr datatype="evr_string" operation="less than">0:4.3.9-3.9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050839003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.5-11.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050839005" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.5-18.2</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050840003" version="503">
  <evr datatype="evr_string" operation="less than">1:2.02-9.8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050840005" version="503">
  <evr datatype="evr_string" operation="less than">1:3.00-11.10</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050843003" version="502">
  <evr datatype="evr_string" operation="less than">0:9.24-11.30.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050848003" version="503">
  <evr datatype="evr_string" operation="less than">0:2002e-14</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050850003" version="502">
  <evr datatype="evr_string" operation="less than">1:2002d-12</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050864003" version="502">
  <evr datatype="evr_string" operation="less than">0:039-10.10.EL4.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050867003" version="502">
  <evr datatype="evr_string" operation="less than">0:2.8.2-7.3</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050868003" version="502">
  <evr datatype="evr_string" operation="less than">7:3.3.1-3.6</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050875003" version="502">
  <evr datatype="evr_string" operation="less than">0:7.12.1-8.rhel4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050878003" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.17-13.3.34</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050878005" version="502">
  <evr datatype="evr_string" operation="less than">1:1.1.22-0.rc1.9.9</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050880003" version="502">
  <evr datatype="evr_string" operation="less than">3:5.8.5-24.RHEL4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050881003" version="502">
  <evr datatype="evr_string" operation="less than">2:5.8.0-90.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050881004" version="502">
  <evr datatype="evr_string" operation="less than">2:1.61-90.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050881005" version="502">
  <evr datatype="evr_string" operation="less than">2:2.89-90.4</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:ste:20050881006" version="502">
  <evr datatype="evr_string" operation="less than">2:1.806-90.4</evr>
</rpminfo_state>
</states>

</oval_definitions>

