<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:23:41
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhba:def:20050447" version="302" class="patch">
      <metadata>
        <title>RHBA-2005:447: Updated cdrtools packages
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2005:447-02" ref_url="https://rhn.redhat.com/errata/RHBA-2005-447.html" />
	<description>Cdrecord is an application for recording audio and data CDs. Cdrecord
works with many different brands of CD recorders, fully supports
multi-sessions, and provides human-readable error messages.

The cdrecord package on Red Hat Enterprise Linux does not require setuid
root for use by normal users.  The permissions of the writer device are
changed by pam_console_apply at console login.  Setting the uid of cdrecord
to root opens a vulnerability to possible exploitation.

All users of cdrecord that setuid root should upgrade to these updated
packages, which resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-05-19" />
        <updated date="2005-05-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0806">CVE-2004-0806</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447002" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447003" comment="cdrtools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447004" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447005" comment="cdrecord is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447006" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447007" comment="cdrecord-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20050447008" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.2" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050447009" comment="mkisofs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhba:def:20050675" version="302" class="patch">
      <metadata>
        <title>RHBA-2005:675: gdb bug fix update
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2005:675-02" ref_url="https://rhn.redhat.com/errata/RHBA-2005-675.html" />
	<description>GDB, the GNU debugger, allows debugging of programs written in C, C++,
and other languages, by executing them in a controlled fashion, and then
printing their data.

This updated package addresses the following issues:

- GDB on ia64 had previously implemented a bug fix to work-around a kernel
problem when creating a core file via gcore.  The bug fix caused a
significant slow-down of gcore.

- GDB on Itanium issued an extraneous warning when gcore was used.

- GDB on Itanium could not successfully do an info frame for a signal
trampoline.

- GDB on AMD64 and Intel EM64T had problems attaching to a 32-bit process.

- GDB on AMD64 and Intel EM64T was not properly handling threaded watchpoints.

- GDB could not build with gcc4 when -Werror flag was set.

- GDB had problems printing inherited members of C++ classes.

- A few updates from mainline sources concerning Dwarf2 partial die in
cache support, follow-fork support, interrupted syscall support, and
DW_OP_piece read support.

All users of gdb should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-09-28" />
        <updated date="2005-09-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1704">CVE-2005-1704</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1705">CVE-2005-1705</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhba:tst:20050675002" comment="gdb is earlier than 0:6.3.0.0-1.62" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20050675003" comment="gdb is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050009" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:009: kdelibs, kdebase security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:009-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-009.html" />
	<description>The kdelibs packages include libraries for the K Desktop Environment. The
kdebase packages include core applications for the K Desktop Environment.

Secunia Research discovered a window injection spoofing vulnerability
affecting the Konqueror web browser. This issue could allow a malicious
website to show arbitrary content in a different browser window. The Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1158
to this issue.

A bug was discovered in the way kioslave handles URL-encoded newline (%0a)
characters before the FTP command. It is possible that a specially crafted
URL could be used to execute any ftp command on a remote server, or
potentially send unsolicited email. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

A bug was discovered that can crash KDE screensaver under certain local
circumstances. This could allow an attacker with physical access to the
workstation to take over a locked desktop session. Please note that this
issue only affects Red Hat Enterprise Linux 2.1. The Common Vulnerabilities
and Exposures project has assigned the name CAN-2005-0078 to this issue.

All users of KDE are advised to upgrade to this updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-10" />
        <updated date="2005-02-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1158">CVE-2004-1158</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165">CVE-2004-1165</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0078">CVE-2005-0078</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009002" comment="kdebase is earlier than 6:3.1.3-5.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009003" comment="kdebase is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009004" comment="kdelibs is earlier than 6:3.1.3-6.9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009006" comment="kdebase-devel is earlier than 6:3.1.3-5.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009007" comment="kdebase-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009008" comment="kdelibs-devel is earlier than 6:3.1.3-6.9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050010" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:010: vim security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:010-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-010.html" />
	<description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  It is possible
that a malicious user could create a file containing a specially crafted
modeline which could cause arbitrary command execution when viewed by a
victim.  Please note that this issue only affects users who have modelines
and filetype plugins enabled, which is not the default.  The  Common
Vulnerabilities and Exposures project has assigned the name CAN-2004-1138
to this issue.

All users of VIM are advised to upgrade to these erratum packages,
which contain a backported patch for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-05" />
        <updated date="2005-01-05" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138">CVE-2004-1138</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010002" comment="vim is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010004" comment="vim-X11 is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-X11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010006" comment="vim-common is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010010" comment="vim-minimal is earlier than 1:6.3.046-0.30E.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-minimal is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050011" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:011: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:011-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-011.html" />
	<description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-02" />
        <updated date="2005-02-02" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139">CVE-2004-1139</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1140">CVE-2004-1140</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141">CVE-2004-1141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142">CVE-2004-1142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0006">CVE-2005-0006</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007">CVE-2005-0007</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0008">CVE-2005-0008</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0009">CVE-2005-0009</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010">CVE-2005-0010</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084">CVE-2005-0084</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011002" comment="ethereal is earlier than 0:0.10.9-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050012" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:012: krb5 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:012-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-012.html" />
	<description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

Additionally a temporary file bug was found in the Kerberos krb5-send-pr
program.  It is possible that an attacker could create a temporary file
that would allow an arbitrary file to be overwritten which the victim has
write access to.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0971 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-19" />
        <updated date="2005-01-19" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0971">CVE-2004-0971</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1189">CVE-2004-1189</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012002" comment="krb5 is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012004" comment="krb5-devel is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012006" comment="krb5-libs is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012008" comment="krb5-server is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012010" comment="krb5-workstation is earlier than 0:1.2.7-38" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050013" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:013: cups security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:013-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-013.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow was found in the CUPS pdftops filter, which uses code
from the Xpdf package.  An attacker who has the ability to send a malicious
PDF file to a printer could possibly execute arbitrary code as the "lp"
user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1125 to this issue.

A buffer overflow was found in the ParseCommand function in the hpgltops
program. An attacker who has the ability to send a malicious HPGL file to a
printer could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1267 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit these buffer overflow
vulnerabilities on x86 architectures.

The lppasswd utility ignores write errors when modifying the CUPS passwd
file.  A local user who is able to fill the associated file system could
corrupt the CUPS password file or prevent future uses of lppasswd.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility does not verify that the passwd.new file is different
from STDERR, which could allow local users to control output to passwd.new
via certain user input that triggers an error message.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1270 to this issue.

In addition to these security issues, two other problems not relating
to security have been fixed:

Resuming a job with "lp -H resume", which had previously been held with "lp
-H hold" could cause the scheduler to stop.  This has been fixed in later
versions of CUPS, and has been backported in these updated packages.

The cancel-cups(1) man page is a symbolic link to another man page.  The
target of this link has been corrected.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1267">CVE-2004-1267</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1268">CVE-2004-1268</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269">CVE-2004-1269</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1270">CVE-2004-1270</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013002" comment="cups is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013004" comment="cups-devel is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013006" comment="cups-libs is earlier than 1:1.1.17-13.3.22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050018" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:018: xpdf security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:018-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-018.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf packages should upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-12" />
        <updated date="2005-01-12" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018002" comment="xpdf is earlier than 1:2.02-9.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050019" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:019: libtiff security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:019-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-019.html" />
	<description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

iDEFENSE has reported an integer overflow bug that affects libtiff. An
attacker who has the ability to trick a user into opening a malicious TIFF
file could cause the application linked to libtiff to crash or possibly
execute arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin reported another integer overflow in the tiffdump 
utility.  An atacker who has the ability to trick a user into opening a
malicious TIFF file with tiffdump could possibly execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308">CVE-2004-1308</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183">CVE-2004-1183</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019002" comment="libtiff is earlier than 0:3.5.7-22.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019004" comment="libtiff-devel is earlier than 0:3.5.7-22.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050021" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:021: kdegraphics security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:021-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-021.html" />
	<description>The kdegraphics package contains graphics applications for the K Desktop
Environment.

During a source code audit, Chris Evans discovered a number of integer
overflow bugs that affect libtiff. The kfax application contains a copy of
the libtiff code used for parsing TIFF files and is therefore affected by
these bugs. An attacker who has the ability to trick a user into opening a
malicious TIFF file could cause kfax to crash or possibly execute arbitrary
code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-0886 and CAN-2004-0804 to these issues.

Additionally, a number of buffer overflow bugs that affect libtiff have
been found. The kfax application contains a copy of the libtiff code used
for parsing TIFF files and is therefore affected by these bugs. An attacker
who has the ability to trick a user into opening a malicious TIFF file
could cause kfax to crash or possibly execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0803 to this issue.

Users of kfax should upgrade to these updated packages, which contain
backported patches and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-04-14" />
        <updated date="2005-04-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803">CVE-2004-0803</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886">CVE-2004-0886</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804">CVE-2004-0804</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021002" comment="kdegraphics is earlier than 7:3.1.3-3.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021004" comment="kdegraphics-devel is earlier than 7:3.1.3-3.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050025" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:025: exim security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:025-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-025.html" />
	<description>Exim is a mail transport agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. 

A buffer overflow was discovered in the spa_base64_to_bits function in
Exim, as originally obtained from Samba code.  If SPA authentication is
enabled, a remote attacker may be able to exploit this vulnerability to
execute arbitrary code as the 'exim' user.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to
this issue.  Please note that SPA authentication is not enabled by default
in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and
dns_build_reverse functions in Exim.  A local user can trigger these flaws
by executing exim with carefully crafted command line arguments and may be
able to gain the privileges of the 'exim' account.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0021">CVE-2005-0021</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0022">CVE-2005-0022</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025002" comment="exim is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025003" comment="exim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025004" comment="exim-doc is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025005" comment="exim-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025006" comment="exim-mon is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025007" comment="exim-mon is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025008" comment="exim-sa is earlier than 0:4.43-1.RHEL4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050025009" comment="exim-sa is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050026" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:026: tetex security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:026-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-026.html" />
	<description>The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-16" />
        <updated date="2005-03-16" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026002" comment="tetex is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026003" comment="tetex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026004" comment="tetex-afm is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026005" comment="tetex-afm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026006" comment="tetex-doc is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026007" comment="tetex-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026008" comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026009" comment="tetex-dvips is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026010" comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026011" comment="tetex-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026012" comment="tetex-latex is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026013" comment="tetex-latex is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026014" comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050026015" comment="tetex-xdvi is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050032" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:032: php security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:032-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-032.html" />
	<description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Flaws including possible information disclosure, double free, and negative
reference index array underflow were found in the deserialization code of
PHP. PHP applications may use the unserialize function on untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1019 to
this issue.

A flaw in the exif extension of PHP was found which lead to a stack
overflow. An attacker could create a carefully crafted image file in such
a way which, if parsed by a PHP script using the exif extension, could
cause a crash or potentially execute arbitrary code. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1065 to this issue.

Flaws were found in shmop_write, pack, and unpack PHP functions. These
functions are not normally passed user supplied data, so would require a
malicious PHP script to be exploited. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1018 to
this issue.

Users of PHP should upgrade to these updated packages, which contain fixes
for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1018">CVE-2004-1018</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1019">CVE-2004-1019</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1065">CVE-2004-1065</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032002" comment="php is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032003" comment="php is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032004" comment="php-devel is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032005" comment="php-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032006" comment="php-domxml is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032007" comment="php-domxml is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032008" comment="php-gd is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032009" comment="php-gd is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032010" comment="php-imap is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032011" comment="php-imap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032012" comment="php-ldap is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032013" comment="php-ldap is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032014" comment="php-mbstring is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032015" comment="php-mbstring is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032016" comment="php-mysql is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032017" comment="php-mysql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032018" comment="php-ncurses is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032019" comment="php-ncurses is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032020" comment="php-odbc is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032021" comment="php-odbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032022" comment="php-pear is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032023" comment="php-pear is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032024" comment="php-pgsql is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032025" comment="php-pgsql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032026" comment="php-snmp is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032027" comment="php-snmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032028" comment="php-xmlrpc is earlier than 0:4.3.9-3.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050032029" comment="php-xmlrpc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050033" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:033: alsa-lib security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:033-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-033.html" />
	<description>The alsa-lib package provides a library of functions for communication with
kernel sound drivers.

A flaw in the alsa mixer code was discovered that caused stack
execution protection to be disabled for the libasound.so library.  
The effect of this flaw is that stack execution protection, through NX or
Exec-Shield, would be disabled for any application linked to libasound. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0087 to this issue

Users are advised to upgrade to this updated package, which contains a
patched version of the library which correctly enables stack execution
protection.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0087">CVE-2005-0087</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033002" comment="alsa-lib is earlier than 0:1.0.6-5.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033003" comment="alsa-lib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033004" comment="alsa-lib-devel is earlier than 0:1.0.6-5.RHEL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050033005" comment="alsa-lib-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050034" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:034: xpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:034-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-034.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An
attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf. An attacker could construct a carefully crafted PDF file that could
cause Xpdf to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf. An attacker could
construct a carefully crafted PDF file that could cause Xpdf to crash or
possibly execute arbitrary code when opened. This issue was assigned the
name CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org).  Red Hat Enterprise Linux 4 contained a fix for this
issue, but it was found to be incomplete and left 64-bit architectures
vulnerable.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0206 to this issue.

All users of Xpdf should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050034002" comment="xpdf is earlier than 1:3.00-11.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050035" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:035: libtiff security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:035-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-035.html" />
	<description>The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

infamous41md discovered integer overflow flaws in libtiff.  An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to overflow a heap buffer when the
file was opened by a victim.  Due to the nature of the overflow it is
unlikely that it is possible to use this flaw to execute arbitrary code. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1308 to this issue. 

Dmitry V. Levin discovered an integer overflow flaw in libtiff.  An
attacker could create a carefully crafted TIFF file in such a way that it
could cause an application linked with libtiff to crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1183 to this issue. 

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308">CVE-2004-1308</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1183">CVE-2004-1183</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050035002" comment="libtiff is earlier than 0:3.6.1-8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019003" comment="libtiff is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050035004" comment="libtiff-devel is earlier than 0:3.6.1-8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050019005" comment="libtiff-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050036" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:036: vim security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:036-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-036.html" />
	<description>VIM (Vi IMproved) is an updated and improved version of the vi screen-based
editor.

Ciaran McCreesh discovered a modeline vulnerability in VIM.  An attacker
could create a text file containing a specially crafted modeline which
could cause arbitrary command execution when viewed by a victim using VIM. 
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-1138 to this issue.  Please note that this issue only affects
users who have modelines and filetype plugins enabled, which is not the
default.  

The Debian Security Audit Project discovered an insecure temporary file
usage in VIM.  A local user could overwrite or create files as a different
user who happens to run one of the the vulnerable utilities.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0069 to this issue. 

All users of VIM are advised to upgrade to these erratum packages,
which contain backported patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1138">CVE-2004-1138</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0069">CVE-2005-0069</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036002" comment="vim is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010003" comment="vim is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036004" comment="vim-X11 is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010005" comment="vim-X11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036006" comment="vim-common is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010007" comment="vim-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036008" comment="vim-enhanced is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010009" comment="vim-enhanced is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050036010" comment="vim-minimal is earlier than 1:6.3.046-0.40E.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050010011" comment="vim-minimal is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050037" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:037: ethereal security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:037-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-037.html" />
	<description>Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal.  On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization.  (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084) 

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1139">CVE-2004-1139</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1140">CVE-2004-1140</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1141">CVE-2004-1141</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1142">CVE-2004-1142</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0006">CVE-2005-0006</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0007">CVE-2005-0007</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0008">CVE-2005-0008</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0009">CVE-2005-0009</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0010">CVE-2005-0010</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0084">CVE-2005-0084</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050037002" comment="ethereal is earlier than 0:0.10.9-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011003" comment="ethereal is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050037004" comment="ethereal-gnome is earlier than 0:0.10.9-1.EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050011005" comment="ethereal-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050038" version="304" class="patch">
      <metadata>
        <title>RHSA-2005:038: mozilla security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:038-04" ref_url="https://rhn.redhat.com/errata/RHSA-2005-038.html" />
	<description>Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

iSEC Security Research has discovered a buffer overflow bug in the way
Mozilla handles NNTP URLs.  If a user visits a malicious web page or is
convinced to click on a malicious link, it may be possible for an attacker
to execute arbitrary code on the victim's machine.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1316 to this issue.

Users of Mozilla should upgrade to these updated packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-13" />
        <updated date="2005-01-13" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316">CVE-2004-1316</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038002" comment="mozilla is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038003" comment="mozilla is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038004" comment="mozilla-chat is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038005" comment="mozilla-chat is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038006" comment="mozilla-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038007" comment="mozilla-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038008" comment="mozilla-dom-inspector is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038009" comment="mozilla-dom-inspector is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038010" comment="mozilla-js-debugger is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038011" comment="mozilla-js-debugger is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038012" comment="mozilla-mail is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038013" comment="mozilla-mail is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038014" comment="mozilla-nspr is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038015" comment="mozilla-nspr is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038016" comment="mozilla-nspr-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038017" comment="mozilla-nspr-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038018" comment="mozilla-nss is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038019" comment="mozilla-nss is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038020" comment="mozilla-nss-devel is earlier than 37:1.4.3-3.0.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050038021" comment="mozilla-nss-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050039" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:039: enscript security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:039-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-039.html" />
	<description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences. A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document. An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments. These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184">CVE-2004-1184</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185">CVE-2004-1185</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186">CVE-2004-1186</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039002" comment="enscript is earlier than 0:1.6.1-24.4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050040" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:040: enscript security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:040-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-040.html" />
	<description>GNU enscript converts ASCII files to PostScript.

Enscript has the ability to interpret special escape sequences.  A flaw was
found in the handling of the epsf command used to insert inline EPS files
into a document.  An attacker could create a carefully crafted ASCII file
which made use of the epsf pipe command in such a way that it could execute
arbitrary commands if the file was opened with enscript by a victim.  The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1184 to this issue.

Additional flaws in Enscript were also discovered which can only be
triggered by executing enscript with carefully crafted command line
arguments.  These flaws therefore only have a security impact if enscript
is executed by other programs and passed untrusted data from remote users.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2004-1185 and CAN-2004-1186 to these issues.

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1184">CVE-2004-1184</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1185">CVE-2004-1185</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1186">CVE-2004-1186</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050040002" comment="enscript is earlier than 0:1.6.1-28.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050039003" comment="enscript is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050043" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:043: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:043-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-043.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

This advisory includes fixes for several security issues:

iSEC Security Research discovered a VMA handling flaw in the uselib(2)
system call of the Linux kernel.  A local user could make use of this
flaw to gain elevated (root) privileges.  The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1235 to
this issue.

A flaw was discovered where an executable could cause a VMA overlap leading
to a crash.  A local user could trigger this flaw by creating a carefully
crafted a.out binary on 32-bit systems or a carefully crafted ELF binary
on Itanium systems.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0003 to this issue.

iSEC Security Research discovered a flaw in the page fault handler code
that could lead to local users gaining elevated (root) privileges on
multiprocessor machines.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0001 to this issue. A patch
that coincidentally fixed this issue was committed to the Update 4 kernel
release in December 2004.  Therefore Red Hat Enterprise Linux 3 kernels
provided by RHBA-2004:550 and subsequent updates are not vulnerable to
this issue.

A flaw in the system call filtering code in the audit subsystem included
in Red Hat Enterprise Linux 3 allowed a local user to cause a crash when
auditing was enabled.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-1237 to this issue.

Olaf Kirch discovered that the recent security fixes for cmsg_len handling
(CAN-2004-1016) broke 32-bit compatibility on 64-bit platforms such as
AMD64 and Intel EM64T. A patch to correct this issue is included.

A recent Internet Draft by Fernando Gont recommended that ICMP Source
Quench messages be ignored by hosts.  A patch to ignore these messages is
included.

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-18" />
        <updated date="2005-01-18" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791">CVE-2004-0791</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1074">CVE-2004-1074</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1235">CVE-2004-1235</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1237">CVE-2004-1237</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0003">CVE-2005-0003</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043002" comment="kernel is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043004" comment="kernel-smp is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043005" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043006" comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043007" comment="kernel-smp-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043008" comment="kernel-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043009" comment="kernel-unsupported is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043010" comment="kernel-BOOT is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043011" comment="kernel-BOOT is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043012" comment="kernel-doc is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043013" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043014" comment="kernel-source is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043015" comment="kernel-source is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043016" comment="kernel-hugemem is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043017" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.2.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050043019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050045" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:045: krb5 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:045-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-045.html" />
	<description>Kerberos is a networked authentication system that uses a trusted third
party (a KDC) to authenticate clients and servers to each other.

A heap based buffer overflow bug was found in the administration library of
Kerberos 1.3.5 and earlier.  This bug could allow an authenticated remote
attacker to execute arbitrary commands on a realm's master Kerberos KDC. 
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1189 to this issue.

All users of krb5 should upgrade to these updated packages, which contain
backported security patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1189">CVE-2004-1189</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045002" comment="krb5 is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012003" comment="krb5 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045004" comment="krb5-devel is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012005" comment="krb5-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045006" comment="krb5-libs is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012007" comment="krb5-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045008" comment="krb5-server is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012009" comment="krb5-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050045010" comment="krb5-workstation is earlier than 0:1.3.4-10" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050012011" comment="krb5-workstation is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050049" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:049: cups security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:049-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-049.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit these buffer overflow
vulnerabilities on x86 architectures.

All users of cups should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049002" comment="cups is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049004" comment="cups-devel is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050049006" comment="cups-libs is earlier than 1:1.1.17-13.3.24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050053" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:053: CUPS security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:053-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-053.html" />
	<description>The Common UNIX Printing System provides a portable printing layer for
UNIX(R) operating systems.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects CUPS due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause CUPS to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects the CUPS pdftops filter due to a shared codebase.  An attacker
who has the ability to send a malicious PDF file to a printer could
possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the ParseCommand function in the
hpgltops program. An attacker who has the ability to send a malicious HPGL
file to a printer could possibly execute arbitrary code as the "lp" user.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1267 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects the CUPS pdftops filter due to a shared codebase.
An attacker who has the ability to send a malicious PDF file to a printer
could possibly execute arbitrary code as the "lp" user. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

The lppasswd utility was found to ignore write errors when modifying the
CUPS passwd file. A local user who is able to fill the associated file
system could corrupt the CUPS password file or prevent future uses of
lppasswd. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-1268 and CAN-2004-1269 to these issues.

The lppasswd utility was found to not verify that the passwd.new file is
different from STDERR, which could allow local users to control output to
passwd.new via certain user input that triggers an error message. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2004-1270 to this issue.

All users of cups should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1267">CVE-2004-1267</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1268">CVE-2004-1268</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1269">CVE-2004-1269</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1270">CVE-2004-1270</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053002" comment="cups is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013003" comment="cups is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013005" comment="cups-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050053006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050013007" comment="cups-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050057" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:057: gpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:057-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-057.html" />
	<description>GPdf is a viewer for Portable Document Format (PDF) files for GNOME. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened.  This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.

Users should update to this erratum package which contains backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0206">CVE-2005-0206</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050057002" comment="gpdf is earlier than 0:2.8.2-4.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050057003" comment="gpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050059" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:059: xpdf security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:059-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-059.html" />
	<description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

A buffer overflow flaw was found when processing the /Encrypt /Length tag.
An attacker could construct a carefully crafted PDF file that could cause
Xpdf to crash or possibly execute arbitrary code when opened. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0064 to this issue.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to exploit this vulnerability on x86
architectures.

All users of the Xpdf package should upgrade to this updated package,
which resolves this issue</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050059002" comment="xpdf is earlier than 1:2.02-9.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050018003" comment="xpdf is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050060" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:060: squid security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:060-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-060.html" />
	<description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious webpage
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious Web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious Web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094">CVE-2005-0094</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0095">CVE-2005-0095</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0096">CVE-2005-0096</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097">CVE-2005-0097</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0173">CVE-2005-0173</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0174">CVE-2005-0174</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175">CVE-2005-0175</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211">CVE-2005-0211</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241">CVE-2005-0241</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060002" comment="squid is earlier than 7:2.5.STABLE6-3.4E.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050061" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:061: squid security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-061.html" />
	<description>Squid is a full-featured Web proxy cache.

A buffer overflow flaw was found in the Gopher relay parser. This bug
could allow a remote Gopher server to crash the Squid proxy that reads data
from it. Although Gopher servers are now quite rare, a malicious web page
(for example) could redirect or contain a frame pointing to an attacker's
malicious gopher server. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0094 to this issue.

An integer overflow flaw was found in the WCCP message parser. It is
possible to crash the Squid server if an attacker is able to send a
malformed WCCP message with a spoofed source address matching Squid's
"home router". The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0095 to this issue.

A memory leak was found in the NTLM fakeauth_auth helper. It is possible
that an attacker could place the Squid server under high load, causing the
NTML fakeauth_auth helper to consume a large amount of memory, resulting in
a denial of service. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0096 to this issue.

A NULL pointer de-reference bug was found in the NTLM fakeauth_auth helper.
It is possible for an attacker to send a malformed NTLM type 3 message,
causing the Squid server to crash. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0097 to
this issue.

A username validation bug was found in squid_ldap_auth. It is possible for
a username to be padded with spaces, which could allow a user to bypass
explicit access control rules or confuse accounting. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0173 to this issue.

The way Squid handles HTTP responses was found to need strengthening. It is
possible that a malicious web server could send a series of HTTP responses
in such a way that the Squid cache could be poisoned, presenting users with
incorrect webpages. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2005-0174 and CAN-2005-0175 to
these issues.

A bug was found in the way Squid handled oversized HTTP response headers.
It is possible that a malicious web server could send a specially crafted
HTTP header which could cause the Squid cache to be poisoned, presenting
users with incorrect webpages.  The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2005-0241 to this issue.

A buffer overflow bug was found in the WCCP message parser. It is possible
that an attacker could send a malformed WCCP message which could crash the
Squid server or execute arbitrary code. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0211
to this issue.

Users of Squid should upgrade to this updated package, which contains
backported patches, and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-11" />
        <updated date="2005-02-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0094">CVE-2005-0094</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0095">CVE-2005-0095</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0096">CVE-2005-0096</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0097">CVE-2005-0097</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0173">CVE-2005-0173</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0174">CVE-2005-0174</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0175">CVE-2005-0175</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0211">CVE-2005-0211</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0241">CVE-2005-0241</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050061002" comment="squid is earlier than 7:2.5.STABLE3-6.3E.7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050060003" comment="squid is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050065" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:065: kdelibs security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:065-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-065.html" />
	<description>The kdelibs packages include libraries for the K Desktop Environment.

Two flaws were found in the sandbox environment used to run Java-applets in
the Konqueror web browser. If a user has Java enabled in Konqueror and
visits a malicious website, the website could run a carefully crafted
Java-applet and obtain escalated privileges allowing reading and writing of
arbitrary files with the privileges of the victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1145 to this issue.

A flaw was discovered in the FTP kioslave.  KDE applications such as
Konqueror could be forced to execute arbitrary FTP commands via a carefully
crafted ftp URL.  The URL could also be crafted in such a way as to send an
arbitrary email via SMTP.  An attacker could make use of this flaw if a
victim visits a malicious web site. The Common Vulnerabilities and
Exposures project has assigned the name CAN-2004-1165 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1145">CVE-2004-1145</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1165">CVE-2004-1165</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050065002" comment="kdelibs is earlier than 6:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009005" comment="kdelibs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050065004" comment="kdelibs-devel is earlier than 6:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050009009" comment="kdelibs-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050066" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:066: kdegraphics security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:066-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-066.html" />
	<description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a pdf file viewer. 

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that
also affects kpdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause kpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects kpdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause kpdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf which also affects
kpdf due to a shared codebase. An attacker could construct a carefully
crafted PDF file that could cause kpdf to crash or possibly execute
arbitrary code when opened. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888">CVE-2004-0888</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125">CVE-2004-1125</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0064">CVE-2005-0064</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050066002" comment="kdegraphics is earlier than 7:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021003" comment="kdegraphics is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050066004" comment="kdegraphics-devel is earlier than 7:3.3.1-3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050021005" comment="kdegraphics-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050068" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:068: less security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:068-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-068.html" />
	<description>The less utility is a text file browser that resembles more, but has
extended capabilities.

Victor Ashik discovered a heap based buffer overflow in less, caused by a
patch added to the less package in Red Hat Enterprise Linux 3. An attacker
could construct a carefully crafted file that could cause less to crash or
possibly execute arbitrary code when opened.  The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0086
to this issue.  Note that this issue only affects the version of less
distributed with Red Hat Enterprise Linux 3.

Red Hat believes that the Exec-Shield technology (enabled by default since
Update 3) will block attempts to remotely exploit this vulnerability on x86
architectures.

All users of the less package should upgrade to this updated package,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-01-26" />
        <updated date="2005-01-26" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0086">CVE-2005-0086</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050068002" comment="less is earlier than 0:378-12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050068003" comment="less is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050069" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:069: perl security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:069-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-069.html" />
	<description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer.  The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. 

Users should update to this erratum package which disables the temporary
PID file unless configured.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-01" />
        <updated date="2005-02-01" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0077">CVE-2005-0077</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050069002" comment="perl-DBI is earlier than 0:1.32-9" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050069003" comment="perl-DBI is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050070" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:070: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:070-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-070.html" />
	<description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An
attacker could execute arbitrary code on a victim's machine if they were
able to trick the victim into opening a file with a specially crafted name.
 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible
that a TIFF image file with an invalid tag could cause ImageMagick to
crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a
specially crafted TIFF image file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible
that a specially crafted PSD file could cause ImageMagick to crash. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser.  It is possible
that an attacker could execute arbitrary code by tricking a user into
opening a specially crafted SGI image file. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to
this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-03-23" />
        <updated date="2005-03-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005">CVE-2005-0005</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0397">CVE-2005-0397</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0759">CVE-2005-0759</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0760">CVE-2005-0760</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0761">CVE-2005-0761</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0762">CVE-2005-0762</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20050447001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070002" comment="ImageMagick is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070004" comment="ImageMagick-c++ is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070006" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070008" comment="ImageMagick-devel is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070010" comment="ImageMagick-perl is earlier than 0:5.5.6-13" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050071" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:071: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:071-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-071.html" />
	<description>ImageMagick is an image display and manipulation tool for the X Window
System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the
ImageMagick image handler. An attacker could create a carefully crafted
Photoshop Document (PSD) image in such a way that it would cause
ImageMagick to execute arbitrary code when processing the image. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0005 to this issue.

Users of ImageMagick should upgrade to these updated packages, which
contain a backported patch, and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2005 Red Hat, Inc.</rights>
        <issued date="2005-02-15" />
        <updated date="2005-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005">CVE-2005-0005</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20050025001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071002" comment="ImageMagick is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071004" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071006" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071008" comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20050071010" comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20050070011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20050072" version="302" class="patch">
      <metadata>
        <title>RHSA-2005:072: perl-DBI security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2005:072-02" ref_url="https://rhn.redhat.com/errata/RHSA-2005-072.html" />
	<description>DBI is a database access Application Programming Interface (API) for
the Perl programming language. 

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner.  A 