<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-09-30T09:51:41
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20070001" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0001: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0001-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0001.html" />
          <reference source="CVE" ref_id="CVE-2006-5870" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5870.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Several integer overflow bugs were found in the OpenOffice.org WMF file
processor. An attacker could create a carefully crafted WMF file that could
cause OpenOffice.org to execute arbitrary code when the file was opened by
a victim. (CVE-2006-5870)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-03" />
        <updated date="2007-01-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5870.html">CVE-2006-5870</cve>
                <bugzilla href="http://bugzilla.redhat.com/217347" id="217347">CVE-2006-5870 WMF heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001006" comment="openoffice.org-i18n is earlier than 0:1.1.2-35.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001002" comment="openoffice.org is earlier than 0:1.1.2-35.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001004" comment="openoffice.org-libs is earlier than 0:1.1.2-35.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001010" comment="openoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001009" comment="openoffice.org is earlier than 0:1.1.5-6.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001013" comment="openoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001011" comment="openoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070002" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0002: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0002.html" />
          <reference source="CVE" ref_id="CVE-2006-6101" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6101.html" />
          <reference source="CVE" ref_id="CVE-2006-6102" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6102.html" />
          <reference source="CVE" ref_id="CVE-2006-6103" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6103.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides the
core functionality for the Linux graphical desktop.

iDefense reported three integer overflow flaws in the XFree86 Render and
DBE extensions. A malicious authorized client could exploit this issue to
cause a denial of service (crash) or potentially execute arbitrary code
with root privileges on the XFree86 server. (CVE-2006-6101, CVE-2006-6102,
CVE-2006-6103)

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-10" />
        <updated date="2007-01-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6101.html">CVE-2006-6101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6102.html">CVE-2006-6102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6103.html">CVE-2006-6103</cve>
                <bugzilla href="http://bugzilla.redhat.com/218870" id="218870">CVE-2006-6101 Multiple XFree86 integer overflows (CVE-2006-6102, CVE-2006-6103)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002048" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002049" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002044" comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002045" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002058" comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002059" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002036" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002037" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002004" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002005" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002038" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002039" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002018" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002019" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002014" comment="XFree86-doc is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002002" comment="XFree86 is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002056" comment="XFree86-libs is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002057" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002040" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002041" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002010" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002011" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002032" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002033" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002022" comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002023" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002012" comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002013" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002060" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002061" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002034" comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002035" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002008" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002009" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002054" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002055" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002042" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002043" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002026" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002027" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002016" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002017" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002028" comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002029" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002020" comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002021" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002006" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002007" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002052" comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002053" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002050" comment="XFree86-twm is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002051" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002024" comment="XFree86-tools is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002025" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002046" comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002047" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070002030" comment="XFree86-devel is earlier than 0:4.3.0-115.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002031" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070003" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0003: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0003.html" />
          <reference source="CVE" ref_id="CVE-2006-6101" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6101.html" />
          <reference source="CVE" ref_id="CVE-2006-6102" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6102.html" />
          <reference source="CVE" ref_id="CVE-2006-6103" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6103.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported three integer overflow flaws in the X.org Render and DBE
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the X.org server. (CVE-2006-6101, CVE-2006-6102, CVE-2006-6103)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-10" />
        <updated date="2007-01-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6101.html">CVE-2006-6101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6102.html">CVE-2006-6102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6103.html">CVE-2006-6103</cve>
                <bugzilla href="http://bugzilla.redhat.com/218871" id="218871">CVE-2006-6101 Multiple xorg-x11 integer overflows (CVE-2006-6102, CVE-2006-6103)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003022" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003023" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003026" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003027" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003014" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003015" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003036" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003037" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003008" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003009" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003006" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003007" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003004" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003005" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003012" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003028" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003029" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003020" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003021" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003034" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003035" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003032" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003033" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003030" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003031" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003024" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003018" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003019" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003016" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003017" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070003010" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003011" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070008" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0008: dbus security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0008-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2006-6107" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6107.html" />
    
    <description>D-BUS is a system for sending messages between applications. It is used
both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Kimmo Hämäläinen discovered a flaw in the way D-BUS processes certain
messages. It is possible for a local unprivileged D-BUS process to disrupt
the ability of another D-BUS process to receive messages. (CVE-2006-6107)

Users of dbus are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-08" />
        <updated date="2007-02-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6107.html">CVE-2006-6107</cve>
                <bugzilla href="http://bugzilla.redhat.com/218055" id="218055">CVE-2006-6107 D-Bus denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070008010" comment="dbus-x11 is earlier than 0:0.22-12.EL.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070008011" comment="dbus-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070008006" comment="dbus-python is earlier than 0:0.22-12.EL.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070008007" comment="dbus-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070008004" comment="dbus-devel is earlier than 0:0.22-12.EL.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070008005" comment="dbus-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070008002" comment="dbus is earlier than 0:0.22-12.EL.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070008003" comment="dbus is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070008008" comment="dbus-glib is earlier than 0:0.22-12.EL.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070008009" comment="dbus-glib is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070011" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0011: libgsf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0011.html" />
          <reference source="CVE" ref_id="CVE-2006-4514" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4514.html" />
    
    <description>The GNOME Structured File Library is a utility library for reading and
writing structured file formats.

A heap based buffer overflow flaw was found in the way GNOME Structured
File Library processes and certain OLE documents. If an person opened a
specially crafted OLE file, it could cause the client application to crash or
execute arbitrary code. (CVE-2006-4514)

Users of GNOME Structured File Library should upgrade to these updated
packages, which contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-11" />
        <updated date="2007-01-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4514.html">CVE-2006-4514</cve>
                <bugzilla href="http://bugzilla.redhat.com/217949" id="217949">CVE-2006-4514 libgsf heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070011004" comment="libgsf-devel is earlier than 0:1.6.0-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070011005" comment="libgsf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070011002" comment="libgsf is earlier than 0:1.6.0-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070011003" comment="libgsf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070011008" comment="libgsf-devel is earlier than 0:1.10.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070011005" comment="libgsf-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070011007" comment="libgsf is earlier than 0:1.10.1-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070011003" comment="libgsf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070014" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0014: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0014-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0014.html" />
          <reference source="CVE" ref_id="CVE-2006-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4538.html" />
          <reference source="CVE" ref_id="CVE-2006-4813" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4813.html" />
          <reference source="CVE" ref_id="CVE-2006-4814" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4814.html" />
          <reference source="CVE" ref_id="CVE-2006-5174" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5174.html" />
          <reference source="CVE" ref_id="CVE-2006-5619" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5619.html" />
          <reference source="CVE" ref_id="CVE-2006-5751" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5751.html" />
          <reference source="CVE" ref_id="CVE-2006-5753" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5753.html" />
          <reference source="CVE" ref_id="CVE-2006-5754" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5754.html" />
          <reference source="CVE" ref_id="CVE-2006-5757" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5757.html" />
          <reference source="CVE" ref_id="CVE-2006-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5823.html" />
          <reference source="CVE" ref_id="CVE-2006-6053" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6053.html" />
          <reference source="CVE" ref_id="CVE-2006-6054" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6054.html" />
          <reference source="CVE" ref_id="CVE-2006-6056" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6056.html" />
          <reference source="CVE" ref_id="CVE-2006-6106" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6106.html" />
          <reference source="CVE" ref_id="CVE-2006-6535" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6535.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below: 

* a flaw in the get_fdb_entries function of the network bridging support
that allowed a local user to cause a denial of service (crash) or allow a
potential privilege escalation (CVE-2006-5751, Important)

* an information leak in the _block_prepare_write function that allowed a
local user to read kernel memory (CVE-2006-4813, Important)

* an information leak in the copy_from_user() implementation on s390 and
s390x platforms that allowed a local user to read kernel memory
(CVE-2006-5174, Important)

* a flaw in the handling of /proc/net/ip6_flowlabel that allowed a local
user to cause a denial of service (infinite loop) (CVE-2006-5619, Important)

* a flaw in the AIO handling that allowed a local user to cause a denial of
 service (panic) (CVE-2006-5754, Important)

* a race condition in the mincore system core that allowed a local user to
cause a denial of service (system hang) (CVE-2006-4814, Moderate)

* a flaw in the ELF handling on ia64 and sparc architectures which
triggered a cross-region memory mapping and allowed a local user to cause a
denial of service (CVE-2006-4538, Moderate)

* a flaw in the dev_queue_xmit function of the network subsystem that
allowed a local user to cause a denial of service (data corruption)
(CVE-2006-6535, Moderate)

* a flaw in the handling of CAPI messages over Bluetooth that allowed a
remote system to cause a denial of service or potential code execution.
This flaw is only exploitable if a privileged user establishes a connection
to a malicious remote device (CVE-2006-6106, Moderate)

* a flaw in the listxattr system call that allowed a local user to cause a
denial of service (data corruption) or potential privilege escalation. To
successfully exploit this flaw the existence of a bad inode is required
first (CVE-2006-5753, Moderate)

* a flaw in the __find_get_block_slow function that allowed a local
privileged user to cause a denial of service (CVE-2006-5757, Low)

* various flaws in the supported filesystems that allowed a local
privileged user to cause a denial of service (CVE-2006-5823, CVE-2006-6053,
CVE-2006-6054, CVE-2006-6056, Low)

In addition to the security issues described above, fixes for the following
bugs were included:

* initialization error of the tg3 driver with some BCM5703x network card

* a memory leak in the audit subsystem

* x86_64 nmi watchdog timeout is too short

* ext2/3 directory reads fail intermittently

Red Hat would like to thank Dmitriy Monakhov and Kostantin Khorenko for
reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architecture and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-01-30" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4538.html">CVE-2006-4538</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4813.html">CVE-2006-4813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4814.html">CVE-2006-4814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5174.html">CVE-2006-5174</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5619.html">CVE-2006-5619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5751.html">CVE-2006-5751</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5753.html">CVE-2006-5753</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5754.html">CVE-2006-5754</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5757.html">CVE-2006-5757</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5823.html">CVE-2006-5823</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6053.html">CVE-2006-6053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6054.html">CVE-2006-6054</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6056.html">CVE-2006-6056</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6106.html">CVE-2006-6106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6535.html">CVE-2006-6535</cve>
                <bugzilla href="http://bugzilla.redhat.com/180663" id="180663">CVE-2006-4814 Race condition in mincore can cause "ps -ef" to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/205335" id="205335">CVE-2006-4538 Local DoS with corrupted ELF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/206328" id="206328">CVE-2006-5757 Linux kernel Filesystem Mount Dead Loop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/207463" id="207463">CVE-2006-4813 Information leak in __block_prepare_write()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/209435" id="209435">CVE-2006-5174 copy_from_user information leak on s390</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/212144" id="212144">CVE-2006-6535 unbalanced local_bh_enable() in dev_queue_xmit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/213214" id="213214">CVE-2006-5619 Lockup via /proc/net/ip6_flowlabel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/213921" id="213921">SAN file systems becoming read-only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/214288" id="214288">CVE-2006-5757 ISO9660 __find_get_block_slow() denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/216452" id="216452">CVE-2006-5751 Linux kernel get_fdb_entries() integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/216958" id="216958">CVE-2006-5823 zlib_inflate memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217011" id="217011">CVE-2006-6056 SELinux superblock_doinit denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217021" id="217021">CVE-2006-6054 ext2_check_page denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217030" id="217030">CVE-2006-6053 ext3fs_dirhash denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/218602" id="218602">CVE-2006-6106 Multiple problems in net/bluetooth/cmtp/capi.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/220677" id="220677">CVE-2006-5753 listxattr syscall can corrupt user space programs [rhel-4.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/220971" id="220971">CVE-2006-5754 kernel panic in aio_free_ring()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014002" comment="kernel is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014018" comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014004" comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014006" comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014014" comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014010" comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014016" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070014012" comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070015" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0015: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0015-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0015.html" />
          <reference source="CVE" ref_id="CVE-2006-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2440.html" />
          <reference source="CVE" ref_id="CVE-2006-5456" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5456.html" />
          <reference source="CVE" ref_id="CVE-2006-5868" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5868.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Several security flaws were discovered in the way ImageMagick decodes DCM,
PALM, and SGI graphic files.  An attacker may be able to execute arbitrary
code on a victim's machine if they were able to trick the victim into
opening a specially crafted image file (CVE-2006-5456, CVE-2006-5868).

A heap overflow flaw was found in ImageMagick.  An attacker may be able to
execute arbitrary code on a victim's machine if they were able to trick the
victim into opening a specially crafted file (CVE-2006-2440).  This issue
only affected the version of ImageMagick distributed with Red Hat
Enterprise Linux 4.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-15" />
        <updated date="2007-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2440.html">CVE-2006-2440</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5456.html">CVE-2006-5456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5868.html">CVE-2006-5868</cve>
                <bugzilla href="http://bugzilla.redhat.com/192278" id="192278">CVE-2006-2440 ImageMagick heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/210921" id="210921">CVE-2006-5456 Overflows in GraphicsMagick and ImageMagick's DCM and PALM handling routines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217558" id="217558">CVE-2006-5868 Insufficient boundary check in ImageMagick's SGIDecode()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015008" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015009" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015004" comment="ImageMagick-devel is earlier than 0:5.5.6-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015006" comment="ImageMagick-perl is earlier than 0:5.5.6-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015002" comment="ImageMagick is earlier than 0:5.5.6-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015010" comment="ImageMagick-c++ is earlier than 0:5.5.6-24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015011" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015016" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015009" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015015" comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015005" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015017" comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015007" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015013" comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015003" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070015014" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070015011" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070018" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0018: fetchmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0018.html" />
          <reference source="CVE" ref_id="CVE-2005-4348" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4348.html" />
          <reference source="CVE" ref_id="CVE-2006-5867" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5867.html" />
    
    <description>Fetchmail is a remote mail retrieval and forwarding utility.

A denial of service flaw was found when Fetchmail was run in multidrop
mode.  A malicious mail server could send a message without headers which
would cause Fetchmail to crash (CVE-2005-4348).  This issue did not affect
the version of Fetchmail shipped with Red Hat Enterprise Linux 2.1 or 3.

A flaw was found in the way Fetchmail used TLS encryption to connect to
remote hosts.  Fetchmail provided no way to enforce the use of TLS
encryption and would not authenticate POP3 protocol connections properly
(CVE-2006-5867).  This update corrects this issue by enforcing TLS
encryption when the "sslproto" configuration directive is set to "tls1".  

Users of Fetchmail should update to these packages, which contain 
backported patches to correct these issues.

Note: This update may break configurations which assumed that Fetchmail
would use plain-text authentication if TLS encryption is not supported by
the POP3 server even if the "sslproto" directive is set to "tls1".  If you
are using a custom configuration that depended on this behavior you will
need to modify your configuration appropriately after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-01-31" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4348.html">CVE-2005-4348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5867.html">CVE-2006-5867</cve>
                <bugzilla href="http://bugzilla.redhat.com/176266" id="176266">CVE-2005-4348 Fetchmail DOS by malicious server in multidrop mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/221981" id="221981">CVE-2006-5867 fetchmail not enforcing TLS for POP3 properly</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018002" comment="fetchmail is earlier than 0:6.2.0-3.el3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018005" comment="fetchmail is earlier than 0:6.2.5-6.el4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070019" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0019: gtk2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0019-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0019.html" />
          <reference source="CVE" ref_id="CVE-2007-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0010.html" />
    
    <description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System.

A bug was found in the way the gtk2 GdkPixbufLoader() function processed
invalid input.   Applications linked against gtk2 could crash if they
loaded a malformed image file. (CVE-2007-0010)

Users of gtk2 are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-01-24" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0010.html">CVE-2007-0010</cve>
                <bugzilla href="http://bugzilla.redhat.com/218932" id="218932">CVE-2007-0010 GdbPixbufLoader fails to handle invalid input from Evolution correctly</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070019002" comment="gtk2 is earlier than 0:2.4.13-22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070019003" comment="gtk2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070019004" comment="gtk2-devel is earlier than 0:2.4.13-22" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070019005" comment="gtk2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070022" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0022: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0022-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0022.html" />
          <reference source="CVE" ref_id="CVE-2006-6142" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6142.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP.

Several cross-site scripting bugs were discovered in SquirrelMail.  An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL.  (CVE-2006-6142) 

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct these issues. 

Notes:
- After installing this update, users are advised to restart their
httpd service to ensure that the updated version functions correctly.
- config.php should NOT be modified, please modify config_local.php instead.
- Known Bug: The configuration generator may potentially produce bad
options that interfere with the operation of this application.  Applying
specific config changes to config_local.php manually is recommended.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-01-31" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6142.html">CVE-2006-6142</cve>
                <bugzilla href="http://bugzilla.redhat.com/218294" id="218294">CVE-2006-6142 Three XSS issues in SquirrelMail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022002" comment="squirrelmail is earlier than 0:1.4.8-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022005" comment="squirrelmail is earlier than 0:1.4.8-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070033" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0033: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0033-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0033.html" />
          <reference source="CVE" ref_id="CVE-2007-0238" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0238.html" />
          <reference source="CVE" ref_id="CVE-2007-0239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0239.html" />
          <reference source="CVE" ref_id="CVE-2007-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1466.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

iDefense reported an integer overflow flaw in libwpd, a library used
internally to OpenOffice.org for handling Word Perfect documents.  An
attacker could create a carefully crafted Word Perfect file that could
cause OpenOffice.org to crash or possibly execute arbitrary code if the
file was opened by a victim. (CVE-2007-1466)

John Heasman discovered a stack overflow in the StarCalc parser in
OpenOffice.org.  An attacker could create a carefully crafted StarCalc file
that could cause OpenOffice.org to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way OpenOffice.org handled hyperlinks.  An
attacker could create an OpenOffice.org document which could run commands
if a victim opened the file and clicked on a malicious hyperlink. 
(CVE-2007-0239)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.

Red Hat would like to thank Fridrich Štrba for alerting us to the issue
CVE-2007-1466 and providing a patch, and John Heasman for
CVE-2007-0238.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-22" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0238.html">CVE-2007-0238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0239.html">CVE-2007-0239</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1466.html">CVE-2007-1466</cve>
                <bugzilla href="http://bugzilla.redhat.com/223801" id="223801">CVE-2007-1466 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/226966" id="226966">CVE-2007-0238 StarCalc overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/228008" id="228008">CVE-2007-0239 hyperlink escaping issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033006" comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033002" comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033004" comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033013" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033009" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033011" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070033010" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070044" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0044: bind security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0044-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0044.html" />
          <reference source="CVE" ref_id="CVE-2007-0494" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0494.html" />
    
    <description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses.  On
servers that had enabled DNSSEC validation, this could allow an remote
attacker to cause a denial of service.  (CVE-2007-0494)

For users of Red Hat Enterprise Linux 3, the previous BIND update caused an
incompatible change to the default configuration that resulted in rndc not
sharing the key with the named daemon. This update corrects this bug and
restores the behavior prior to that update.

Updating the bind package in Red Hat Enterprise Linux 3 could result in
nonfunctional configuration in case the bind-libs package was not updated.
This update corrects this bug by adding the correct dependency on bind-libs.

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-06" />
        <updated date="2007-02-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0494.html">CVE-2007-0494</cve>
                <bugzilla href="http://bugzilla.redhat.com/202012" id="202012">rndc.conf change breaks working bind config</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225222" id="225222">CVE-2007-0494 BIND dnssec denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044010" comment="bind-utils is earlier than 20:9.2.4-20.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044008" comment="bind-chroot is earlier than 20:9.2.4-20.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044004" comment="bind-devel is earlier than 20:9.2.4-20.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044002" comment="bind is earlier than 20:9.2.4-20.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044006" comment="bind-libs is earlier than 20:9.2.4-20.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044016" comment="bind-utils is earlier than 20:9.2.4-24.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044015" comment="bind-devel is earlier than 20:9.2.4-24.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044014" comment="bind-chroot is earlier than 20:9.2.4-24.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044013" comment="bind is earlier than 20:9.2.4-24.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070044017" comment="bind-libs is earlier than 20:9.2.4-24.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070055" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0055: libwpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0055-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0055.html" />
          <reference source="CVE" ref_id="CVE-2007-0002" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0002.html" />
          <reference source="CVE" ref_id="CVE-2007-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1466.html" />
    
    <description>libwpd is a library for reading and converting Word Perfect documents.

iDefense reported several overflow bugs in libwpd.  An attacker could
create a carefully crafted Word Perfect file that could cause an
application linked with libwpd, such as OpenOffice, to crash or possibly
execute arbitrary code if the file was opened by a victim. (CVE-2007-0002)

All users are advised to upgrade to these updated packages, which contain a
backported fix for this issue.

Red Hat would like to thank Fridrich Štrba for alerting us to these issues
and providing a patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-16" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0002.html">CVE-2007-0002</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1466.html">CVE-2007-1466</cve>
                <bugzilla href="http://bugzilla.redhat.com/222808" id="222808">CVE-2007-0002 buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055006" comment="libwpd-tools is earlier than 0:0.8.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070055007" comment="libwpd-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055004" comment="libwpd-devel is earlier than 0:0.8.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070055005" comment="libwpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055002" comment="libwpd is earlier than 0:0.8.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070055003" comment="libwpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070057" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0057: bind security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0057-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0057.html" />
          <reference source="CVE" ref_id="CVE-2007-0493" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0493.html" />
          <reference source="CVE" ref_id="CVE-2007-0494" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0494.html" />
    
    <description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses. On
servers that had enabled DNSSEC validation, this could allow a remote
attacker to cause a denial of service. (CVE-2007-0494)

A use-after-free flaw was found in BIND. On servers that have recursion
enabled, this could allow a remote attacker to cause a denial of service. 
(CVE-2007-0493)

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0493.html">CVE-2007-0493</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0494.html">CVE-2007-0494</cve>
                <bugzilla href="http://bugzilla.redhat.com/224445" id="224445">CVE-2007-0493 BIND might crash after attempting to read free()-ed memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225229" id="225229">CVE-2007-0494 BIND dnssec denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057014" comment="bind-libbind-devel is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057015" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057010" comment="bind-utils is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057011" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057006" comment="bind-devel is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057007" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057004" comment="bind-chroot is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057005" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057008" comment="bind-sdb is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057009" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057002" comment="bind is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057016" comment="bind-libs is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057017" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070057012" comment="caching-nameserver is earlier than 30:9.3.3-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057013" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070060" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0060: samba security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0060.html" />
          <reference source="CVE" ref_id="CVE-2007-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0452.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources.
(CVE-2007-0452)

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-15" />
        <updated date="2007-02-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0452.html">CVE-2007-0452</cve>
                <bugzilla href="http://bugzilla.redhat.com/225513" id="225513">CVE-2007-0452 Samba smbd denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060006" comment="samba-client is earlier than 0:3.0.9-1.3E.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060008" comment="samba-common is earlier than 0:3.0.9-1.3E.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060002" comment="samba is earlier than 0:3.0.9-1.3E.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060004" comment="samba-swat is earlier than 0:3.0.9-1.3E.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060013" comment="samba-client is earlier than 0:3.0.10-1.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060012" comment="samba-common is earlier than 0:3.0.10-1.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060011" comment="samba is earlier than 0:3.0.10-1.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070060014" comment="samba-swat is earlier than 0:3.0.10-1.4E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070061" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0061: samba security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0061.html" />
          <reference source="CVE" ref_id="CVE-2007-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0452.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources
(CVE-2007-0452).

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0452.html">CVE-2007-0452</cve>
                <bugzilla href="http://bugzilla.redhat.com/225519" id="225519">CVE-2007-0452 Samba smbd denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070061008" comment="samba-client is earlier than 0:3.0.23c-2.el5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070061004" comment="samba-common is earlier than 0:3.0.23c-2.el5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061005" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070061002" comment="samba is earlier than 0:3.0.23c-2.el5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070061006" comment="samba-swat is earlier than 0:3.0.23c-2.el5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061007" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070064" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0064: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0064-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0064.html" />
          <reference source="CVE" ref_id="CVE-2006-5540" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5540.html" />
          <reference source="CVE" ref_id="CVE-2007-0555" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0555.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw was found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit this issue (CVE-2007-0555).

A denial of service flaw was found affecting the PostgreSQL server running
on Red Hat Enterprise Linux 4 systems. An authenticated user could execute
an SQL command which could crash the PostgreSQL server. (CVE-2006-5540)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 7.4.16 or 7.3.18, which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-07" />
        <updated date="2007-02-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5540.html">CVE-2006-5540</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0555.html">CVE-2007-0555</cve>
                <bugzilla href="http://bugzilla.redhat.com/212358" id="212358">CVE-2006-5540 New version fixes three different crash vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225493" id="225493">CVE-2007-0555 PostgreSQL arbitrary memory read flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064008" comment="rh-postgresql-docs is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064004" comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064005" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064016" comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064017" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064002" comment="rh-postgresql is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064018" comment="rh-postgresql-python is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064014" comment="rh-postgresql-pl is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064012" comment="rh-postgresql-devel is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064022" comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064023" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064020" comment="rh-postgresql-server is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064021" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064010" comment="rh-postgresql-libs is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064011" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064006" comment="rh-postgresql-test is earlier than 0:7.3.18-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064007" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064045" comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064046" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064031" comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064032" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064035" comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064036" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064041" comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064042" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064037" comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064038" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064029" comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064030" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064039" comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064040" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064025" comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064026" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064043" comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064044" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064033" comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064034" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070064027" comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064028" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070065" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0065: bluez-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0065-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0065.html" />
          <reference source="CVE" ref_id="CVE-2006-6899" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6899.html" />
    
    <description>The bluez-utils package contains Bluetooth daemons and utilities.

A flaw was found in the Bluetooth HID daemon (hidd). A remote attacker
would have been able to inject keyboard and mouse events via a Bluetooth
connection without any authorization. (CVE-2006-6899)

Note that Red Hat Enterprise Linux does not come with the Bluetooth HID
daemon enabled by default.

Users of bluez-utils are advised to upgrade to these updated packages, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-14" />
        <updated date="2007-05-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6899.html">CVE-2006-6899</cve>
                <bugzilla href="http://bugzilla.redhat.com/227014" id="227014">CVE-2006-6899 Bluetooth HID key events injection flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070065004" comment="bluez-utils-cups is earlier than 0:2.10-2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070065005" comment="bluez-utils-cups is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070065002" comment="bluez-utils is earlier than 0:2.10-2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070065003" comment="bluez-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070066" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0066: wireshark security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0066.html" />
          <reference source="CVE" ref_id="CVE-2007-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0456.html" />
          <reference source="CVE" ref_id="CVE-2007-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0457.html" />
          <reference source="CVE" ref_id="CVE-2007-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0458.html" />
          <reference source="CVE" ref_id="CVE-2007-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0459.html" />
    
    <description>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's LLT, IEEE 802.11,
http, and tcp protocol dissectors. It was possible for Wireshark to crash
or stop responding if it read a malformed packet off the network.
(CVE-2007-0456, CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.5, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0456.html">CVE-2007-0456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0457.html">CVE-2007-0457</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0458.html">CVE-2007-0458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0459.html">CVE-2007-0459</cve>
                <bugzilla href="http://bugzilla.redhat.com/225689" id="225689">CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225781" id="225781">CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066002" comment="wireshark is earlier than 0:0.99.5-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066004" comment="wireshark-gnome is earlier than 0:0.99.5-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066007" comment="wireshark is earlier than 0:0.99.5-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066009" comment="wireshark-gnome is earlier than 0:0.99.5-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066012" comment="wireshark is earlier than 0:0.99.5-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070066013" comment="wireshark-gnome is earlier than 0:0.99.5-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070068" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0068: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0068-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0068.html" />
          <reference source="CVE" ref_id="CVE-2006-5540" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5540.html" />
          <reference source="CVE" ref_id="CVE-2006-5541" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5541.html" />
          <reference source="CVE" ref_id="CVE-2006-5542" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5542.html" />
          <reference source="CVE" ref_id="CVE-2007-0555" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0555.html" />
          <reference source="CVE" ref_id="CVE-2007-0556" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0556.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

Two flaws were found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit these issues (CVE-2007-0555,
CVE-2007-0556).

Several denial of service flaws were found in the PostgreSQL server.  An
authenticated user could execute certain SQL commands which could crash the
PostgreSQL server (CVE-2006-5540, CVE-2006-5541, CVE-2006-5542).

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 8.1.8 which corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5540.html">CVE-2006-5540</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5541.html">CVE-2006-5541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5542.html">CVE-2006-5542</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0555.html">CVE-2007-0555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0556.html">CVE-2007-0556</cve>
                <bugzilla href="http://bugzilla.redhat.com/216411" id="216411">CVE-2006-5540 New version fixes three different crash vulnerabilities (CVE-2006-5541 CVE-2006-5542)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225496" id="225496">CVE-2007-0555 PostgreSQL arbitrary memory read flaws (CVE-2007-0556)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227688" id="227688">Attribute type error when updating varchar column</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068004" comment="postgresql-docs is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068005" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068008" comment="postgresql-devel is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068009" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068020" comment="postgresql-test is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068021" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068012" comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068013" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068010" comment="postgresql-libs is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068011" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068006" comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068007" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068002" comment="postgresql is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068018" comment="postgresql-server is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068019" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068016" comment="postgresql-pl is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068017" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070068014" comment="postgresql-python is earlier than 0:8.1.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068015" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070069" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0069: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0069-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0069.html" />
          <reference source="CVE" ref_id="CVE-2007-0238" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0238.html" />
          <reference source="CVE" ref_id="CVE-2007-0239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0239.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

John Heasman discovered a stack overflow in the StarCalc parser in
OpenOffice.  An attacker could create a carefully crafted StarCalc file
that could cause OpenOffice.org to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way OpenOffice.org handled hyperlinks.  An
attacker could create an OpenOffice.org document which could run commands
if a victim opened the file and clicked on a malicious hyperlink. 
(CVE-2007-0239)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-22" />
        <updated date="2007-03-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0238.html">CVE-2007-0238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0239.html">CVE-2007-0239</cve>
                <bugzilla href="http://bugzilla.redhat.com/226967" id="226967">CVE-2007-0238 StarCalc overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/228002" id="228002">CVE-2007-0239 hyperlink escaping issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069002" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069060" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069061" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069130" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069131" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069092" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069093" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069142" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069143" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069080" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069081" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069016" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069017" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069040" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069041" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069036" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069037" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069058" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069059" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069112" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069113" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069136" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069137" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069076" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069077" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069082" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069083" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069010" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069011" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069096" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069097" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069030" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069031" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069140" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069141" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069090" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069091" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069118" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069119" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069022" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069023" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069048" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069049" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069148" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069149" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069134" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069135" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069052" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069053" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069020" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069021" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069012" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069013" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069126" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069127" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069138" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069139" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069114" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069115" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069108" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069109" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069056" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069057" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069098" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069099" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069106" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069107" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069124" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069125" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069024" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069025" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069044" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069045" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069014" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069015" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069006" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069007" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069100" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069101" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069116" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069117" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069062" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069063" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069086" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069087" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069028" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069029" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069094" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069095" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069042" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069043" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069104" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069105" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069084" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069085" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069110" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069111" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069070" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069071" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069034" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069035" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069102" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069103" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069064" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069065" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069072" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069073" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069144" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069145" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069032" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069122" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069123" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069074" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069075" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069004" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069005" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069066" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069067" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069046" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069047" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069078" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069079" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069050" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069051" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069008" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069009" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069146" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069147" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069038" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069039" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069054" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069055" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069088" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069089" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069026" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069027" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069128" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069129" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069068" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069069" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069132" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069133" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069120" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069121" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070069018" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069019" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070074" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0074: spamassassin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0074-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0074.html" />
          <reference source="CVE" ref_id="CVE-2007-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0451.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

A flaw was found in the way SpamAssassin processes HTML email containing
URIs. A carefully crafted mail message could cause SpamAssassin to consume
significant resources. If a number of these messages are sent, this could
lead to a denial of service, potentially delaying or preventing the
delivery  of email.
(CVE-2007-0451)

Users of SpamAssassin should upgrade to these updated packages which
contain version 3.1.8 which is not vulnerable to these issues.  

This is an upgrade from SpamAssassin version 3.0.6 to 3.1.8, which contains
many bug fixes and spam detection enhancements. Further details are
available in the SpamAssassin 3.1 changelog and upgrade guide.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-21" />
        <updated date="2007-02-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0451.html">CVE-2007-0451</cve>
                <bugzilla href="http://bugzilla.redhat.com/228586" id="228586">CVE-2007-0451 Spamassassin DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070074002" comment="spamassassin is earlier than 0:3.1.8-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070074003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070075" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0075: spamassassin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0075-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0075.html" />
          <reference source="CVE" ref_id="CVE-2007-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0451.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

A flaw was found in the way SpamAssassin processes HTML email containing
URIs. A carefully crafted mail message could cause SpamAssassin to consume
significant resources. If a number of these messages are sent, this could
lead to a denial of service, potentially delaying or preventing the
delivery  of email. (CVE-2007-0451)

Users of SpamAssassin should upgrade to these updated packages which
contain version 3.1.8 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-13" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0451.html">CVE-2007-0451</cve>
                <bugzilla href="http://bugzilla.redhat.com/228587" id="228587">CVE-2007-0451 Spamassassin DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070075002" comment="spamassassin is earlier than 0:3.1.8-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070075003" comment="spamassassin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070076" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0076: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0076-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0076.html" />
          <reference source="CVE" ref_id="CVE-2007-0906" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0906.html" />
          <reference source="CVE" ref_id="CVE-2007-0907" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0907.html" />
          <reference source="CVE" ref_id="CVE-2007-0908" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0908.html" />
          <reference source="CVE" ref_id="CVE-2007-0909" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0909.html" />
          <reference source="CVE" ref_id="CVE-2007-0910" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0910.html" />
          <reference source="CVE" ref_id="CVE-2007-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0988.html" />
          <reference source="CVE" ref_id="CVE-2007-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1380.html" />
          <reference source="CVE" ref_id="CVE-2007-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1701.html" />
          <reference source="CVE" ref_id="CVE-2007-1825" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1825.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A number of buffer overflow flaws were found in the PHP session extension,
the str_replace() function, and the imap_mail_compose() function.
If very long strings under the control of an attacker are passed to the
str_replace() function then an integer overflow could occur in memory
allocation.  If a script uses the imap_mail_compose() function to create a
new MIME message based on an input body from an untrusted source, it could
result in a heap overflow.  An attacker who is able to access a PHP
application affected by any these issues could trigger these flaws and
possibly execute arbitrary code as the 'apache' user. (CVE-2007-0906)

If unserializing untrusted data on 64-bit platforms, the zend_hash_init()
function can be forced to enter an infinite loop, consuming CPU resources
for a limited length of time, until the script timeout alarm aborts
execution of the script. (CVE-2007-0988)

If the wddx extension is used to import WDDX data from an untrusted source,
certain WDDX input packets may allow a random portion of heap memory to be
exposed. (CVE-2007-0908)

If the odbc_result_all() function is used to display data from a database,
and the contents of the database table are under the control of an
attacker, a format string vulnerability is possible which could lead to the
execution of arbitrary code.  (CVE-2007-0909)

A one byte memory read will always occur before the beginning of a buffer,
which could be triggered for example by any use of the header() function in
a script.  However it is unlikely that this would have any effect.
(CVE-2007-0907)

Several flaws in PHP could allows attackers to "clobber" certain
super-global variables via unspecified vectors. (CVE-2007-0910)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.

Red Hat would like to thank Stefan Esser for his help diagnosing these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-02-19" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0906.html">CVE-2007-0906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0907.html">CVE-2007-0907</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0908.html">CVE-2007-0908</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0909.html">CVE-2007-0909</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0910.html">CVE-2007-0910</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0988.html">CVE-2007-0988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1380.html">CVE-2007-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1701.html">CVE-2007-1701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1825.html">CVE-2007-1825</cve>
                <bugzilla href="http://bugzilla.redhat.com/228858" id="228858">CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909,  CVE-2007-0910, CVE-2007-0988)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076006" comment="php-odbc is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076010" comment="php-mysql is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076002" comment="php is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076004" comment="php-pgsql is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076008" comment="php-devel is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076014" comment="php-imap is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076012" comment="php-ldap is earlier than 0:4.3.2-39.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076035" comment="php-gd is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076036" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076032" comment="php-odbc is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076034" comment="php-mysql is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076017" comment="php is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076023" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076024" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076021" comment="php-mbstring is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076022" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076037" comment="php-pgsql is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076033" comment="php-devel is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076031" comment="php-imap is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076029" comment="php-ncurses is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076030" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076025" comment="php-snmp is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076026" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076019" comment="php-pear is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076020" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076027" comment="php-domxml is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076028" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070076018" comment="php-ldap is earlier than 0:4.3.9-3.22.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070077" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0077: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0077-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0077.html" />
          <reference source="CVE" ref_id="CVE-2006-6077" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6077.html" />
          <reference source="CVE" ref_id="CVE-2007-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0009.html" />
          <reference source="CVE" ref_id="CVE-2007-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0775.html" />
          <reference source="CVE" ref_id="CVE-2007-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0778.html" />
          <reference source="CVE" ref_id="CVE-2007-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2007-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0780.html" />
          <reference source="CVE" ref_id="CVE-2007-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0800.html" />
          <reference source="CVE" ref_id="CVE-2007-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-0994" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0994.html" />
          <reference source="CVE" ref_id="CVE-2007-0995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0995.html" />
          <reference source="CVE" ref_id="CVE-2007-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0996.html" />
          <reference source="CVE" ref_id="CVE-2007-1092" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1092.html" />
          <reference source="CVE" ref_id="CVE-2007-1282" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1282.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A malicious web page could execute JavaScript code in such
a way that may result in SeaMonkey crashing or executing arbitrary code as
the user running SeaMonkey. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way SeaMonkey
processed certain malformed web pages. A malicious web page could display
misleading information which may result in a user unknowingly divulging
sensitive information such as a password. (CVE-2006-6077, CVE-2007-0995,
CVE-2007-0996)

A flaw was found in the way SeaMonkey cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way SeaMonkey displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way SeaMonkey displayed blocked popup windows.
If a user can be convinced to open a blocked popup, it is possible to read
arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
SeaMonkey. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way SeaMonkey handled the "location.hostname" value
during certain browser domain checks. This flaw could allow a malicious web
site to set domain cookies for an arbitrary site, or possibly perform an
XSS attack. (CVE-2007-0981)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain SeaMonkey version 1.0.8 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-02-23" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6077.html">CVE-2006-6077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0008.html">CVE-2007-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0009.html">CVE-2007-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0775.html">CVE-2007-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0777.html">CVE-2007-0777</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0778.html">CVE-2007-0778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0779.html">CVE-2007-0779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0780.html">CVE-2007-0780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0800.html">CVE-2007-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0981.html">CVE-2007-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0994.html">CVE-2007-0994</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0995.html">CVE-2007-0995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0996.html">CVE-2007-0996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1092.html">CVE-2007-1092</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1282.html">CVE-2007-1282</cve>
                <bugzilla href="http://bugzilla.redhat.com/204589" id="204589">mozilla-config points to the wrong places</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229805" id="229805">CVE-2007-0775 Multiple Seamonkey flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229987" id="229987">seamonkey-1.0.8-x (critical) update prevents evolution from starting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230158" id="230158">seamonkey-1.0.8-x (critical) update prevents evolution from starting</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077008" comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077020" comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077018" comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077004" comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077002" comment="seamonkey is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077016" comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077014" comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077012" comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077006" comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077010" comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077023" comment="devhelp is earlier than 0:0.10-0.7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077024" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077025" comment="devhelp-devel is earlier than 0:0.10-0.7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077026" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077035" comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077034" comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077029" comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077033" comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077027" comment="seamonkey is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077028" comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077036" comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077032" comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077030" comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070077031" comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070078" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0078: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0078-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0078.html" />
          <reference source="CVE" ref_id="CVE-2006-6077" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6077.html" />
          <reference source="CVE" ref_id="CVE-2007-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0009.html" />
          <reference source="CVE" ref_id="CVE-2007-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0775.html" />
          <reference source="CVE" ref_id="CVE-2007-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0778.html" />
          <reference source="CVE" ref_id="CVE-2007-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2007-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0780.html" />
          <reference source="CVE" ref_id="CVE-2007-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0800.html" />
          <reference source="CVE" ref_id="CVE-2007-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-0995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0995.html" />
          <reference source="CVE" ref_id="CVE-2007-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0996.html" />
          <reference source="CVE" ref_id="CVE-2007-1092" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1092.html" />
          <reference source="CVE" ref_id="CVE-2007-1282" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1282.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML mail message could execute JavaScript
code in such a way that may result in Thunderbird crashing or executing
arbitrary code as the user running Thunderbird. JavaScript support is
disabled by default in Thunderbird; these issues are not exploitable unless
the user has enabled JavaScript. (CVE-2007-0775, CVE-2007-0777, CVE-2007-1092)

A flaw was found in the way Thunderbird processed text/enhanced and
text/richtext formatted mail message. A specially crafted mail message
could execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2007-1282)

Several cross-site scripting (XSS) flaws were found in the way Thunderbird
processed certain malformed HTML mail messages. A malicious HTML mail
message could display misleading information which may result in a user
unknowingly divulging sensitive information such as a password.
(CVE-2006-6077, CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Thunderbird cached web content on the local
disk. A malicious HTML mail message may be able to inject arbitrary HTML
into a browsing session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious HTML mail message could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Thunderbird displayed blocked popup
windows. If a user can be convinced to open a blocked popup, it is possible
to read arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Thunderbird. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Thunderbird handled the "location.hostname"
value during certain browser domain checks. This flaw could allow a
malicious HTML mail message to set domain cookies for an arbitrary site, or
possibly perform an XSS attack. (CVE-2007-0981)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.10 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-02" />
        <updated date="2007-04-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6077.html">CVE-2006-6077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0008.html">CVE-2007-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0009.html">CVE-2007-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0775.html">CVE-2007-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0777.html">CVE-2007-0777</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0778.html">CVE-2007-0778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0779.html">CVE-2007-0779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0780.html">CVE-2007-0780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0800.html">CVE-2007-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0981.html">CVE-2007-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0995.html">CVE-2007-0995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0996.html">CVE-2007-0996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1092.html">CVE-2007-1092</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1282.html">CVE-2007-1282</cve>
                <bugzilla href="http://bugzilla.redhat.com/166574" id="166574">[PATCH] Thunderbird's remote doesn't allow attachments</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/204453" id="204453">Thunderbird startup script not updated for the add-on based locale</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230542" id="230542">CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1092)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078002" comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070079" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0079: Firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0079-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0079.html" />
          <reference source="CVE" ref_id="CVE-2006-6077" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6077.html" />
          <reference source="CVE" ref_id="CVE-2007-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0009.html" />
          <reference source="CVE" ref_id="CVE-2007-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0775.html" />
          <reference source="CVE" ref_id="CVE-2007-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0778.html" />
          <reference source="CVE" ref_id="CVE-2007-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2007-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0780.html" />
          <reference source="CVE" ref_id="CVE-2007-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0800.html" />
          <reference source="CVE" ref_id="CVE-2007-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-0994" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0994.html" />
          <reference source="CVE" ref_id="CVE-2007-0995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0995.html" />
          <reference source="CVE" ref_id="CVE-2007-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0996.html" />
          <reference source="CVE" ref_id="CVE-2007-1092" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1092.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A malicious web page could execute JavaScript code in such
a way that may result in Firefox crashing or executing arbitrary code as
the user running Firefox. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way Firefox
processed certain malformed web pages. A malicious web page could display
misleading information which may result in a user unknowingly divulging
sensitive information such as a password. (CVE-2006-6077, CVE-2007-0995,
CVE-2007-0996)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Firefox displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Firefox displayed blocked popup windows. If
a user can be convinced to open a blocked popup, it is possible to read
arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Firefox. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Firefox handled the "location.hostname" value
during certain browser domain checks. This flaw could allow a malicious web
site to set domain cookies for an arbitrary site, or possibly perform an
XSS attack. (CVE-2007-0981)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.10 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-23" />
        <updated date="2007-02-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6077.html">CVE-2006-6077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0008.html">CVE-2007-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0009.html">CVE-2007-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0775.html">CVE-2007-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0777.html">CVE-2007-0777</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0778.html">CVE-2007-0778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0779.html">CVE-2007-0779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0780.html">CVE-2007-0780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0800.html">CVE-2007-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0981.html">CVE-2007-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0994.html">CVE-2007-0994</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0995.html">CVE-2007-0995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0996.html">CVE-2007-0996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1092.html">CVE-2007-1092</cve>
                <bugzilla href="http://bugzilla.redhat.com/202352" id="202352">Firefox 1.5.0.5 startup script not updated for the add-on based locale</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229802" id="229802">CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079002" comment="firefox is earlier than 0:1.5.0.10-0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070082" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0082: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0082-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0082.html" />
          <reference source="CVE" ref_id="CVE-2007-0906" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0906.html" />
          <reference source="CVE" ref_id="CVE-2007-0907" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0907.html" />
          <reference source="CVE" ref_id="CVE-2007-0908" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0908.html" />
          <reference source="CVE" ref_id="CVE-2007-0909" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0909.html" />
          <reference source="CVE" ref_id="CVE-2007-0988" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0988.html" />
          <reference source="CVE" ref_id="CVE-2007-0910" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0910.html" />
          <reference source="CVE" ref_id="CVE-2007-1285" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1285.html" />
          <reference source="CVE" ref_id="CVE-2007-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1380.html" />
          <reference source="CVE" ref_id="CVE-2007-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1701.html" />
          <reference source="CVE" ref_id="CVE-2007-1825" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1825.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A number of buffer overflow flaws were found in the PHP session extension;
the str_replace() function; and the imap_mail_compose() function. If very
long strings were passed to the str_replace() function, an integer
overflow could occur in memory allocation. If a script used the
imap_mail_compose() function to create a new MIME message based on an
input body from an untrusted source, it could result in a heap overflow.
An attacker with access to a PHP application affected by any these issues
could trigger the flaws and possibly execute arbitrary code as the
'apache' user. (CVE-2007-0906)

When unserializing untrusted data on 64-bit platforms, the
zend_hash_init() function could be forced into an infinite loop, consuming
CPU resources for a limited time, until the script timeout alarm aborted
execution of the script. (CVE-2007-0988)

If the wddx extension was used to import WDDX data from an untrusted
source, certain WDDX input packets could expose a random portion of heap
memory. (CVE-2007-0908)

If the odbc_result_all() function was used to display data from a
database, and the database table contents were under an attacker's
control, a format string vulnerability was possible which could allow
arbitrary code execution. (CVE-2007-0909)

A one byte memory read always occurs before the beginning of a buffer.
This could be triggered, for example, by any use of the header() function
in a script. However it is unlikely that this would have any effect.
(CVE-2007-0907)

Several flaws in PHP could allow attackers to "clobber" certain
super-global variables via unspecified vectors. (CVE-2007-0910)

An input validation bug allowed a remote attacker to trigger a denial of
service attack by submitting an input variable with a deeply-nested-array.
(CVE-2007-1285)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-13" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0906.html">CVE-2007-0906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0907.html">CVE-2007-0907</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0908.html">CVE-2007-0908</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0909.html">CVE-2007-0909</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0988.html">CVE-2007-0988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0910.html">CVE-2007-0910</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1285.html">CVE-2007-1285</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1380.html">CVE-2007-1380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1701.html">CVE-2007-1701</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1825.html">CVE-2007-1825</cve>
                <bugzilla href="http://bugzilla.redhat.com/229013" id="229013">CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909,  CVE-2007-0910, CVE-2007-0988)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231597" id="231597">CVE-2007-1285 PHP Variable Destructor Deep Recursion Stack Overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082036" comment="php-odbc is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082037" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082034" comment="php-gd is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082035" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082014" comment="php-soap is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082015" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082008" comment="php-common is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082009" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082024" comment="php-mysql is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082025" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082002" comment="php is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082004" comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082005" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082018" comment="php-cli is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082019" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082032" comment="php-mbstring is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082033" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082038" comment="php-xml is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082039" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082022" comment="php-pgsql is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082023" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082020" comment="php-devel is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082021" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082006" comment="php-dba is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082007" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082030" comment="php-imap is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082031" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082016" comment="php-snmp is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082017" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082012" comment="php-ncurses is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082013" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082010" comment="php-bcmath is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082011" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082028" comment="php-ldap is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082029" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070082026" comment="php-pdo is earlier than 0:5.1.6-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082027" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070085" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0085: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0085-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0085.html" />
          <reference source="CVE" ref_id="CVE-2007-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0001.html" />
          <reference source="CVE" ref_id="CVE-2007-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0006.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for two security issues:

* a flaw in the key serial number collision avoidance algorithm of the
keyctl subsystem that allowed a local user to cause a denial of service
(CVE-2007-0006, Important)

* a flaw in the file watch implementation of the audit subsystems that
allowed a local user to cause a denial of service (panic). To exploit this
flaw a privileged user must have previously created a watch for a file 
(CVE-2007-0001, Moderate)

In addition to the security issues described above, a fix for the SCTP
subsystem to address a system crash which may be experienced in Telco
environments has been included.

Red Hat Enterprise Linux 4 users are advised to upgrade their kernels to
the packages associated with their machine architecture and configurations
as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-27" />
        <updated date="2007-02-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0001.html">CVE-2007-0001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0006.html">CVE-2007-0006</cve>
                <bugzilla href="http://bugzilla.redhat.com/223129" id="223129">CVE-2007-0001 kernel panic watching /etc/passwd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/223818" id="223818">kernel panic in sctp module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227495" id="227495">CVE-2007-0006 Key serial number collision problem</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085002" comment="kernel is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085018" comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085004" comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085010" comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085014" comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085012" comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085016" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070085006" comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070086" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0086: gnomemeeting security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0086-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0086.html" />
          <reference source="CVE" ref_id="CVE-2007-1007" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1007.html" />
    
    <description>GnomeMeeting is a tool to communicate with video and audio over the Internet.

A format string flaw was found in the way GnomeMeeting processes certain
messages. If a user is running GnomeMeeting, a remote attacker who can
connect to GnomeMeeting could trigger this flaw and potentially execute
arbitrary code with the privileges of the user. (CVE-2007-1007)

Users of GnomeMeeting should upgrade to these updated packages which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-20" />
        <updated date="2007-02-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1007.html">CVE-2007-1007</cve>
                <bugzilla href="http://bugzilla.redhat.com/229266" id="229266">CVE-2007-1007 gnomemeeting format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070086002" comment="gnomemeeting is earlier than 0:0.96.0-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070086003" comment="gnomemeeting is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070086005" comment="gnomemeeting is earlier than 0:1.0.2-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070086003" comment="gnomemeeting is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070087" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0087: ekiga security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0087-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0087.html" />
          <reference source="CVE" ref_id="CVE-2007-0999" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0999.html" />
          <reference source="CVE" ref_id="CVE-2007-1006" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1006.html" />
    
    <description>Ekiga is a tool to communicate with video and audio over the Internet.

Format string flaws were found in the way Ekiga processes certain messages.
If a user is running Ekiga, a remote attacker who can connect to Ekiga
could trigger this flaw and potentially execute arbitrary code with the
privileges of the user. (CVE-2007-0999, CVE-2007-1006)

Users of Ekiga should upgrade to these updated packages which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-13" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0999.html">CVE-2007-0999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1006.html">CVE-2007-1006</cve>
                <bugzilla href="http://bugzilla.redhat.com/229262" id="229262">CVE-2007-0999 Ekiga format string flaw (CVE-2007-1006)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070087002" comment="ekiga is earlier than 0:2.0.2-7.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070087003" comment="ekiga is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070095" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0095: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0095.html" />
          <reference source="CVE" ref_id="CVE-2007-0956" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0956.html" />
          <reference source="CVE" ref_id="CVE-2007-0957" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0957.html" />
          <reference source="CVE" ref_id="CVE-2007-1216" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1216.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the username handling of the MIT krb5 telnet daemon
(telnetd).  A remote attacker who can access the telnet port of a target
machine could log in as root without requiring a password.  (CVE-2007-0956)

Note that the krb5 telnet daemon is not enabled by default in any version
of Red Hat Enterprise Linux.  In addition, the default firewall rules block
remote access to the telnet port.  This flaw does not affect the telnet
daemon distributed in the telnet-server package.

For users who have enabled the krb5 telnet daemon and have it accessible
remotely, this update should be applied immediately.  

Whilst we are not aware at this time that the flaw is being actively
exploited, we have confirmed that the flaw is very easily exploitable.

This update also fixes two additional security issues:

Buffer overflows were found which affect the Kerberos KDC and the kadmin
server daemon.  A remote attacker who can access the KDC could exploit this
bug to run arbitrary code with the privileges of the KDC or kadmin server
processes.  (CVE-2007-0957)

A double-free flaw was found in the GSSAPI library used by the kadmin
server daemon.  Red Hat Enterprise Linux 4 and 5 contain checks within
glibc that detect double-free flaws. Therefore, on Red Hat Enterprise Linux
4 and 5 successful exploitation of this issue can only lead to a denial of
service.  Applications which use this library in earlier releases of Red
Hat Enterprise Linux may also be affected.  (CVE-2007-1216)

All users are advised to update to these erratum packages which contain a
backported fix to correct these issues.

Red Hat would like to thank MIT and iDefense for reporting these
vulnerabilities.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0956.html">CVE-2007-0956</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0957.html">CVE-2007-0957</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1216.html">CVE-2007-1216</cve>
                <bugzilla href="http://bugzilla.redhat.com/229782" id="229782">CVE-2007-0956 Unauthorized access via krb5-telnet daemon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231528" id="231528">CVE-2007-0957 krb5_klog_syslog() stack buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231537" id="231537">CVE-2007-1216 krb5 double free flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095006" comment="krb5-libs is earlier than 0:1.5-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095007" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095008" comment="krb5-devel is earlier than 0:1.5-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095009" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095010" comment="krb5-server is earlier than 0:1.5-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095011" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095002" comment="krb5 is earlier than 0:1.5-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095004" comment="krb5-workstation is earlier than 0:1.5-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095015" comment="krb5-libs is earlier than 0:1.2.7-61" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095016" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095019" comment="krb5-devel is earlier than 0:1.2.7-61" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095020" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095021" comment="krb5-server is earlier than 0:1.2.7-61" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095022" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095013" comment="krb5 is earlier than 0:1.2.7-61" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095014" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095017" comment="krb5-workstation is earlier than 0:1.2.7-61" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095018" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095026" comment="krb5-libs is earlier than 0:1.3.4-46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095016" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095025" comment="krb5-devel is earlier than 0:1.3.4-46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095020" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095028" comment="krb5-server is earlier than 0:1.3.4-46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095022" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095024" comment="krb5 is earlier than 0:1.3.4-46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095014" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070095027" comment="krb5-workstation is earlier than 0:1.3.4-46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095018" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070097" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0097: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0097-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0097.html" />
          <reference source="CVE" ref_id="CVE-2006-6077" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6077.html" />
          <reference source="CVE" ref_id="CVE-2007-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0009.html" />
          <reference source="CVE" ref_id="CVE-2007-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0775.html" />
          <reference source="CVE" ref_id="CVE-2007-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0778.html" />
          <reference source="CVE" ref_id="CVE-2007-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2007-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0780.html" />
          <reference source="CVE" ref_id="CVE-2007-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0800.html" />
          <reference source="CVE" ref_id="CVE-2007-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-0994" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0994.html" />
          <reference source="CVE" ref_id="CVE-2007-0995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0995.html" />
          <reference source="CVE" ref_id="CVE-2007-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0996.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Flaws were found in the way Firefox executed malformed JavaScript code. A
malicious web page could cause Firefox to crash or allow arbitrary code 
to be executed as the user running Firefox. (CVE-2007-0775, CVE-2007-0777)

Cross-site scripting (XSS) flaws were found in Firefox.  A malicious web
page could display misleading information, allowing a user to unknowingly
divulge sensitive information, such as a password. (CVE-2006-6077, 
CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Firefox processed JavaScript contained in
certain tags.  A malicious web page could cause Firefox to execute
JavaScript code with the privileges of the user running Firefox.
(CVE-2007-0994)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may have been able to inject arbitrary HTML into a
browsing session if the user reloaded a targeted site. (CVE-2007-0778)

Certain web content could overlay Firefox user interface elements such as
the hostname and security indicators.  A malicious web page could trick a
user into thinking they were visiting a different site. (CVE-2007-0779)

Two flaws were found in Firefox's displaying of blocked popup windows. If a
user could be convinced to open a blocked popup, it was possible to read
arbitrary local files, or conduct a cross-site scripting attack against the
user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Firefox. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Firefox handled the "location.hostname" value.
 A malicious web page could set domain cookies for an arbitrary site, or
possibly perform a cross-site scripting attack. (CVE-2007-0981)
	
Users of Firefox are advised to upgrade to this erratum package, containing
Firefox version 1.5.0.10 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6077.html">CVE-2006-6077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0008.html">CVE-2007-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0009.html">CVE-2007-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0775.html">CVE-2007-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0777.html">CVE-2007-0777</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0778.html">CVE-2007-0778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0779.html">CVE-2007-0779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0780.html">CVE-2007-0780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0800.html">CVE-2007-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0981.html">CVE-2007-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0994.html">CVE-2007-0994</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0995.html">CVE-2007-0995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0996.html">CVE-2007-0996</cve>
                <bugzilla href="http://bugzilla.redhat.com/230050" id="230050">CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070097002" comment="devhelp is earlier than 0:0.12-10.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097003" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070097004" comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097005" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070097006" comment="yelp is earlier than 0:2.16.0-14.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097007" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070097010" comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097011" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070097008" comment="firefox is earlier than 0:1.5.0.10-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070099" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0099: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0099-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0099.html" />
          <reference source="CVE" ref_id="CVE-2007-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0005.html" />
          <reference source="CVE" ref_id="CVE-2007-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0006.html" />
          <reference source="CVE" ref_id="CVE-2007-0958" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0958.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the key serial number collision avoidance algorithm of the
keyctl subsystem that allowed a local user to cause a denial of service
(CVE-2007-0006, Important)

* a flaw in the Omnikey CardMan 4040 driver that allowed a local user to
execute arbitrary code with kernel privileges. In order to exploit this
issue, the Omnikey CardMan 4040 PCMCIA card must be present and the local
user must have access rights to the character device created by the driver.
(CVE-2007-0005, Moderate)

* a flaw in the core-dump handling that allowed a local user to create core
dumps from unreadable binaries via PT_INTERP. (CVE-2007-0958, Low)

In addition to the security issues described above, a fix for a kernel
panic in the powernow-k8 module, and a fix for a kernel panic when booting
the Xen domain-0 on system with large memory installations have been included.

Red Hat would like to thank Daniel Roethlisberger for reporting an issue
fixed in this erratum.

Red Hat Enterprise Linux 5 users are advised to upgrade their kernels to
the packages associated with their machine architecture and configurations
as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0005.html">CVE-2007-0005</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0006.html">CVE-2007-0006</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0958.html">CVE-2007-0958</cve>
                <bugzilla href="http://bugzilla.redhat.com/229883" id="229883">CVE-2007-0006 Key serial number collision problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229884" id="229884">CVE-2007-0005 Buffer Overflow in Omnikey CardMan 4040 cmx driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229885" id="229885">CVE-2007-0958 core-dumping unreadable binaries via PT_INTERP</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099004" comment="kernel-headers is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099002" comment="kernel is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099020" comment="kernel-doc is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099010" comment="kernel-devel is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099014" comment="kernel-kdump is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099008" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099012" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070099006" comment="kernel-xen is earlier than 0:2.6.18-8.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070106" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0106: gnupg security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0106.html" />
          <reference source="CVE" ref_id="CVE-2007-1263" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1263.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

Gerardo Richarte discovered that a number of applications that make use of
GnuPG are prone to a vulnerability involving incorrect verification of
signatures and encryption.  An attacker could add arbitrary content to a
signed message in such a way that a receiver of the message would not be
able to distinguish between the properly signed parts of a message and the
forged, unsigned, parts.  (CVE-2007-1263)

Whilst this is not a vulnerability in GnuPG itself, the GnuPG team have
produced a patch to protect against messages with multiple plaintext
packets.  Users should update to these erratum packages which contain the
backported patch for this issue.

Red Hat would like to thank Core Security Technologies for reporting this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-06" />
        <updated date="2007-03-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1263.html">CVE-2007-1263</cve>
                <bugzilla href="http://bugzilla.redhat.com/230456" id="230456">CVE-2007-1263 gnupg signed message spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070106002" comment="gnupg is earlier than 0:1.2.1-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070106003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070106005" comment="gnupg is earlier than 0:1.2.6-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070106003" comment="gnupg is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070107" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0107: gnupg security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0107-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0107.html" />
          <reference source="CVE" ref_id="CVE-2007-1263" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1263.html" />
    
    <description>GnuPG is a utility for encrypting data and creating digital signatures.

Gerardo Richarte discovered that a number of applications that make use of
GnuPG are prone to a vulnerability involving incorrect verification of
signatures and encryption.  An attacker could add arbitrary content to a
signed message in such a way that a receiver of the message would not be
able to distinguish between the properly signed parts of a message and the
forged, unsigned, parts.  (CVE-2007-1263)

Whilst this is not a vulnerability in GnuPG itself, the GnuPG team have
produced a patch to protect against messages with multiple plaintext
packets.  Users should update to these erratum packages which contain the
backported patch for this issue.

Red Hat would like to thank Core Security Technologies for reporting this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-13" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1263.html">CVE-2007-1263</cve>
                <bugzilla href="http://bugzilla.redhat.com/230467" id="230467">CVE-2007-1263 gnupg signed message spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070107002" comment="gnupg is earlier than 0:1.4.5-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070107003" comment="gnupg is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070108" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0108: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0108-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0108.html" />
          <reference source="CVE" ref_id="CVE-2006-6077" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6077.html" />
          <reference source="CVE" ref_id="CVE-2007-0008" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-0009" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0009.html" />
          <reference source="CVE" ref_id="CVE-2007-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0775.html" />
          <reference source="CVE" ref_id="CVE-2007-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0778.html" />
          <reference source="CVE" ref_id="CVE-2007-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2007-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0780.html" />
          <reference source="CVE" ref_id="CVE-2007-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0800.html" />
          <reference source="CVE" ref_id="CVE-2007-0981" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-0995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0995.html" />
          <reference source="CVE" ref_id="CVE-2007-0996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0996.html" />
          <reference source="CVE" ref_id="CVE-2007-1282" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1282.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML mail message could execute JavaScript
code in such a way that may result in Thunderbird crashing or executing
arbitrary code as the user running Thunderbird. JavaScript support is
disabled by default in Thunderbird; these issues are not exploitable unless
the user has enabled JavaScript. (CVE-2007-0775, CVE-2007-0777)

Several cross-site scripting (XSS) flaws were found in the way Thunderbird
processed certain malformed HTML mail messages. A malicious HTML mail
message could display misleading information which may result in a user
unknowingly divulging sensitive information such as a password.
(CVE-2006-6077, CVE-2007-0995, CVE-2007-0996)

A flaw was found in the way Thunderbird processed text/enhanced and
text/richtext formatted mail message. A specially crafted mail message
could execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2007-1282)

A flaw was found in the way Thunderbird cached web content on the local
disk. A malicious HTML mail message may be able to inject arbitrary HTML
into a browsing session if the user reloads a targeted site. (CVE-2007-0778)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious HTML mail message could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking a
user into thinking they are visiting a different site. (CVE-2007-0779)

Two flaws were found in the way Thunderbird displayed blocked popup
windows. If a user can be convinced to open a blocked popup, it is possible
to read arbitrary local files, or conduct an XSS attack against the user.
(CVE-2007-0780, CVE-2007-0800)

Two buffer overflow flaws were found in the Network Security Services (NSS)
code for processing the SSLv2 protocol. Connecting to a malicious secure
web server could cause the execution of arbitrary code as the user running
Thunderbird. (CVE-2007-0008, CVE-2007-0009)

A flaw was found in the way Thunderbird handled the "location.hostname"
value during certain browser domain checks. This flaw could allow a
malicious HTML mail message to set domain cookies for an arbitrary site, or
possibly perform an XSS attack. (CVE-2007-0981)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.10 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-13" />
        <updated date="2007-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6077.html">CVE-2006-6077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0008.html">CVE-2007-0008</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0009.html">CVE-2007-0009</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0775.html">CVE-2007-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0777.html">CVE-2007-0777</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0778.html">CVE-2007-0778</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0779.html">CVE-2007-0779</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0780.html">CVE-2007-0780</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0800.html">CVE-2007-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0981.html">CVE-2007-0981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0995.html">CVE-2007-0995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0996.html">CVE-2007-0996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1282.html">CVE-2007-1282</cve>
                <bugzilla href="http://bugzilla.redhat.com/230562" id="230562">CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1282)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108002" comment="thunderbird is earlier than 0:1.5.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070114" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0114: xen security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0114-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0114.html" />
          <reference source="CVE" ref_id="CVE-2007-0998" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0998.html" />
    
    <description>The Xen package contains the tools for managing the virtual machine monitor
in Red Hat Enterprise Linux virtualization.

A flaw was found affecting the VNC server code in QEMU.  On a
fullyvirtualized guest VM, where qemu monitor mode is enabled, a user who
had access to the VNC server could gain the ability to read arbitrary files
as root in the host filesystem.  (CVE-2007-0998)

In addition to disabling qemu monitor mode, the following bugs were also fixed:

* Fix IA64 fully virtualized (VTi) shadow page table mode initialization.

* Fix network bonding in balanced-rr mode.  Without this update, a network
path loss could result in packet loss.

Users of Xen should update to these erratum packages containing backported
patches which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0998.html">CVE-2007-0998</cve>
                <bugzilla href="http://bugzilla.redhat.com/230295" id="230295">CVE-2007-0998 HVM guest VNC server allows compromise of entire host OS by any VNC console user</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070114002" comment="xen is earlier than 0:3.0.3-25.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070114004" comment="xen-libs is earlier than 0:3.0.3-25.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114005" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070114006" comment="xen-devel is earlier than 0:3.0.3-25.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114007" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070123" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0123: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0123-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0123.html" />
          <reference source="CVE" ref_id="CVE-2007-0720" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0720.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A bug was found in the way CUPS handled SSL negotiation.  A remote user
capable of connecting to the CUPS daemon could cause a denial of service to
other CUPS users.  (CVE-2007-0720)

All users of CUPS should upgrade to these updated packages, which contain
a backported patch introducing a timeout, which prevents connections being
kept open for an arbitrarily long time.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-04-16" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0720.html">CVE-2007-0720</cve>
                <bugzilla href="http://bugzilla.redhat.com/232241" id="232241">CVE-2007-0720 Incomplete SSL negotiation prevents other clients from connecting to CUPS server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123004" comment="cups-lpd is earlier than 1:1.2.4-11.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123005" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123008" comment="cups-devel is earlier than 1:1.2.4-11.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123009" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123006" comment="cups-libs is earlier than 1:1.2.4-11.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123007" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123002" comment="cups is earlier than 1:1.2.4-11.5.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123015" comment="cups-devel is earlier than 1:1.1.17-13.3.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123013" comment="cups-libs is earlier than 1:1.1.17-13.3.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123011" comment="cups is earlier than 1:1.1.17-13.3.42" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123019" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123020" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070123018" comment="cups is earlier than 1:1.1.22-0.rc1.9.18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070124" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0124: file security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0124-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0124.html" />
          <reference source="CVE" ref_id="CVE-2007-1536" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1536.html" />
    
    <description>The file command is used to identify a particular file according to the
type of data contained by the file.

An integer underflow flaw was found in the file utility.  An attacker could
create a carefully crafted file which, if examined by a victim using the
file utility, could lead to arbitrary code execution. (CVE-2007-1536)

This issue did not affect the version of the file utility distributed with
Red Hat Enterprise Linux 2.1 or 3.

Users should upgrade to this erratum package, which contain a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-23" />
        <updated date="2007-03-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1536.html">CVE-2007-1536</cve>
                <bugzilla href="http://bugzilla.redhat.com/233161" id="233161">CVE-2007-1536 file 4.20 fixes a heap overflow in that can result in arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233337" id="233337">CVE-2007-1536 file 4.20 fixes a heap overflow in that can result in arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124002" comment="file is earlier than 0:4.17-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124003" comment="file is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124005" comment="file is earlier than 0:4.10-3.EL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124006" comment="file is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070125" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0125: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0125-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0125.html" />
          <reference source="CVE" ref_id="CVE-2007-1003" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1003.html" />
          <reference source="CVE" ref_id="CVE-2007-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1667.html" />
          <reference source="CVE" ref_id="CVE-2007-1351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1351.html" />
          <reference source="CVE" ref_id="CVE-2007-1352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1352.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides the
core functionality for the Linux graphical desktop.

iDefense reported an integer overflow flaw in the XFree86 XC-MISC
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the XFree86 server. (CVE-2007-1003)

iDefense reported two integer overflows in the way X.org handled various
font files. A malicious local user could exploit these issues to
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-1351, CVE-2007-1352)

An integer overflow flaw was found in the XFree86 XGetPixel() function.
Improper use of this function could cause an application calling it to
function improperly, possibly leading to a crash or arbitrary code
execution. (CVE-2007-1667)

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1003.html">CVE-2007-1003</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1667.html">CVE-2007-1667</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1351.html">CVE-2007-1351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1352.html">CVE-2007-1352</cve>
                <bugzilla href="http://bugzilla.redhat.com/231684" id="231684">CVE-2007-1667 XGetPixel() integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232996" id="232996">CVE-2007-1003 xserver XC-MISC integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234055" id="234055">CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125032" comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002045" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125010" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002049" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125058" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002037" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125024" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002005" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125006" comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002059" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125040" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002019" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125022" comment="XFree86-doc is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002015" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125020" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002039" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125002" comment="XFree86 is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125060" comment="XFree86-libs is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002057" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125044" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002011" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125042" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002041" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125030" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002033" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125016" comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002023" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125008" comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002013" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125048" comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002035" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125046" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002061" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125004" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002009" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125050" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002043" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125018" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002055" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125038" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002017" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125036" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002027" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125034" comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002029" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125028" comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002021" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125012" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002007" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125056" comment="XFree86-tools is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002025" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125026" comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002053" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125014" comment="XFree86-twm is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002051" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125054" comment="XFree86-devel is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002031" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070125052" comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070002047" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070126" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0126: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0126-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0126.html" />
          <reference source="CVE" ref_id="CVE-2007-1003" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1003.html" />
          <reference source="CVE" ref_id="CVE-2007-1351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1351.html" />
          <reference source="CVE" ref_id="CVE-2007-1352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1352.html" />
          <reference source="CVE" ref_id="CVE-2007-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1667.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported an integer overflow flaw in the X.org XC-MISC
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with the
privileges of the X.org server. (CVE-2007-1003)

iDefense reported two integer overflows in the way X.org handled various
font files. A malicious local user could exploit these issues to
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-1351, CVE-2007-1352)

An integer overflow flaw was found in the X.org XGetPixel() function.
Improper use of this function could cause an application calling it to
function improperly, possibly leading to a crash or arbitrary code
execution. (CVE-2007-1667)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1003.html">CVE-2007-1003</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1351.html">CVE-2007-1351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1352.html">CVE-2007-1352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1667.html">CVE-2007-1667</cve>
                <bugzilla href="http://bugzilla.redhat.com/231693" id="231693">CVE-2007-1667 XGetPixel() integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233000" id="233000">CVE-2007-1003 xserver XC-MISC integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234056" id="234056">CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126016" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003023" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126036" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003027" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126008" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003015" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126034" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003009" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126028" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003007" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126024" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003005" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126018" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003037" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126020" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126030" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003029" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126010" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003021" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126026" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003035" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126022" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003033" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126014" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003031" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126012" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126032" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003017" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126006" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003011" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070126004" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003019" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070127" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0127: xorg-x11-server security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0127-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0127.html" />
          <reference source="CVE" ref_id="CVE-2007-1003" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1003.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported an integer overflow flaw in the X.org X11 server XC-MISC
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the X.org server. (CVE-2007-1003)

Users of the X.org X11 server should upgrade to these updated packages,
which contain a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2007-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1003.html">CVE-2007-1003</cve>
                <bugzilla href="http://bugzilla.redhat.com/233001" id="233001">CVE-2007-1003 xserver XC-MISC integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127012" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127013" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127008" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127009" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127004" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127005" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127010" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127011" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127006" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127007" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127002" comment="xorg-x11-server is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127003" comment="xorg-x11-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070127014" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.13.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070127015" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070131" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0131: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0131-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0131.html" />
          <reference source="CVE" ref_id="CVE-2007-1560" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1560.html" />
    
    <description>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A denial of service flaw was found in the way Squid processed the TRACE
request method. It was possible for an attacker behind the Squid proxy
to issue a malformed TRACE request, crashing the Squid daemon child
process. As long as these requests were sent, it would prevent
legitimate usage of the proxy server. (CVE-2007-1560)

This flaw does not affect the version of Squid shipped in Red Hat
Enterprise Linux 2.1, 3, or 4.

Users of Squid should upgrade to this updated package, which contains a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2007-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1560.html">CVE-2007-1560</cve>
                <bugzilla href="http://bugzilla.redhat.com/233253" id="233253">CVE-2007-1560 Squid TRACE DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070131002" comment="squid is earlier than 7:2.6.STABLE6-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070131003" comment="squid is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070132" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0132: libXfont security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0132.html" />
          <reference source="CVE" ref_id="CVE-2007-1351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1351.html" />
          <reference source="CVE" ref_id="CVE-2007-1352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1352.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported two integer overflows in the way X.org handled various
font files. A malicious local user could exploit these issues to
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-1351, CVE-2007-1352)

Users of X.org libXfont should upgrade to these updated packages, which
contain a backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2007-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1351.html">CVE-2007-1351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1352.html">CVE-2007-1352</cve>
                <bugzilla href="http://bugzilla.redhat.com/234058" id="234058">CVE-2007-1351 Multiple font integer overflows (CVE-2007-1352)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070132002" comment="libXfont is earlier than 0:1.2.2-1.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070132003" comment="libXfont is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070132004" comment="libXfont-devel is earlier than 0:1.2.2-1.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070132005" comment="libXfont-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070150" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0150: freetype security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0150-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0150.html" />
          <reference source="CVE" ref_id="CVE-2007-1351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1351.html" />
    
    <description>FreeType is a free, high-quality,  portable font engine.

An integer overflow flaw was found in the way the FreeType font engine
processed BDF font files. If a user loaded a carefully crafted font file
with a program linked against FreeType, it could cause the application to
crash or execute arbitrary code. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2007-1351)

This flaw did not affect the version of FreeType shipped in Red Hat
Enterprise Linux 2.1.

Users of FreeType should upgrade to these updated packages, which contain
a backported patch to correct this issue.

Red Hat would like to thank iDefense for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-16" />
        <updated date="2007-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1351.html">CVE-2007-1351</cve>
                <bugzilla href="http://bugzilla.redhat.com/234228" id="234228">CVE-2007-1351 BDF font integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150002" comment="freetype is earlier than 0:2.2.1-17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150003" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150004" comment="freetype-demos is earlier than 0:2.2.1-17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150005" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150006" comment="freetype-devel is earlier than 0:2.2.1-17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150007" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150013" comment="freetype-utils is earlier than 0:2.1.4-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150014" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150009" comment="freetype is earlier than 0:2.1.4-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150011" comment="freetype-demos is earlier than 0:2.1.4-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150012" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150015" comment="freetype-devel is earlier than 0:2.1.4-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150016" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150020" comment="freetype-utils is earlier than 0:2.1.9-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150014" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150018" comment="freetype is earlier than 0:2.1.9-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150021" comment="freetype-demos is earlier than 0:2.1.9-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150012" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070150019" comment="freetype-devel is earlier than 0:2.1.9-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150016" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070152" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0152: mysql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0152-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0152.html" />
          <reference source="CVE" ref_id="CVE-2006-4226" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4226.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was found in the way MySQL handled case sensitive database names. A
user with the ability to create databases could gain unauthorized access to
other databases hosted by the MySQL server. (CVE-2006-4226)

This flaw does not affect the version of MySQL distributed with Red Hat
Enterprise Linux 2.1, 3, or 5.

All users of the MySQL server are advised to upgrade to these updated
packages, which contain a backported patch which fixes this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-03" />
        <updated date="2007-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4226.html">CVE-2006-4226</cve>
                <bugzilla href="http://bugzilla.redhat.com/203426" id="203426">CVE-2006-4226 mysql-server create database privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070152002" comment="mysql is earlier than 0:4.1.20-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070152008" comment="mysql-server is earlier than 0:4.1.20-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152009" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070152006" comment="mysql-bench is earlier than 0:4.1.20-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152007" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070152004" comment="mysql-devel is earlier than 0:4.1.20-2.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152005" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070153" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0153: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0153-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0153.html" />
          <reference source="CVE" ref_id="CVE-2007-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0455.html" />
          <reference source="CVE" ref_id="CVE-2007-1001" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1001.html" />
          <reference source="CVE" ref_id="CVE-2007-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1718.html" />
          <reference source="CVE" ref_id="CVE-2007-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1583.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A flaw was found in the way the mbstring extension set global variables. A
script which used the mb_parse_str() function to set global variables could
be forced to enable the register_globals configuration option, possibly
resulting in global variable injection. (CVE-2007-1583)

A heap based buffer overflow flaw was discovered in PHP's gd extension. A
script that could be forced to process WBMP images from an untrusted source
could result in arbitrary code execution. (CVE-2007-1001)

A buffer over-read flaw was discovered in PHP's gd extension. A script that
could be forced to write arbitrary string using a JIS font from an
untrusted source could cause the PHP interpreter to crash. (CVE-2007-0455)

A flaw was discovered in the way PHP's mail() function processed header
data. If a script sent mail using a Subject header containing a string from
an untrusted source, a remote attacker could send bulk e-mail to unintended
recipients. (CVE-2007-1718)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-20" />
        <updated date="2007-04-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0455.html">CVE-2007-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1001.html">CVE-2007-1001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1718.html">CVE-2007-1718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1583.html">CVE-2007-1583</cve>
                <bugzilla href="http://bugzilla.redhat.com/235016" id="235016">CVE-2007-1583 mbstring register_globals activation and mail() header injection (CVE-2007-1718)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/235036" id="235036">CVE-2007-1001 gd flaws in wbmp, JIS font handling (CVE-2007-0455)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153018" comment="php-odbc is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082037" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153014" comment="php-soap is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082015" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153008" comment="php-gd is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082035" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153006" comment="php-common is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082009" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153030" comment="php-mysql is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082025" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153002" comment="php is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153016" comment="php-xmlrpc is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082005" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153022" comment="php-cli is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082019" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153036" comment="php-mbstring is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082033" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153034" comment="php-pgsql is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082023" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153004" comment="php-xml is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082039" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153038" comment="php-dba is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082007" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153024" comment="php-devel is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082021" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153028" comment="php-ncurses is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082013" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153026" comment="php-imap is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082031" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153012" comment="php-bcmath is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082011" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153010" comment="php-snmp is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082017" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153032" comment="php-pdo is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082027" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070153020" comment="php-ldap is earlier than 0:5.1.6-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082029" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070155" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0155: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0155-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0155.html" />
          <reference source="CVE" ref_id="CVE-2007-1285" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1285.html" />
          <reference source="CVE" ref_id="CVE-2007-1286" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1286.html" />
          <reference source="CVE" ref_id="CVE-2007-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1583.html" />
          <reference source="CVE" ref_id="CVE-2007-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1711.html" />
          <reference source="CVE" ref_id="CVE-2007-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1718.html" />
          <reference source="CVE" ref_id="CVE-2007-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0455.html" />
          <reference source="CVE" ref_id="CVE-2007-1001" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1001.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A denial of service flaw was found in the way PHP processed a deeply nested
array. A remote attacker could cause the PHP interpreter to crash by
submitting an input variable with a deeply nested array. (CVE-2007-1285) 

A flaw was found in the way PHP's unserialize() function processed data. If
a remote attacker was able to pass arbitrary data to PHP's unserialize()
function, they could possibly execute arbitrary code as the apache user.
(CVE-2007-1286)

A flaw was found in the way the mbstring extension set global variables. A
script which used the mb_parse_str() function to set global variables could
be forced to enable the register_globals configuration option, possibly
resulting in global variable injection. (CVE-2007-1583)

A double free flaw was found in PHP's session_decode() function. If a
remote attacker was able to pass arbitrary data to PHP's session_decode()
function, they could possibly execute arbitrary code as the apache user.
(CVE-2007-1711)

A flaw was discovered in the way PHP's mail() function processed header
data. If a script sent mail using a Subject header containing a string from
an untrusted source, a remote attacker could send bulk e-mail to unintended
recipients. (CVE-2007-1718)

A heap based buffer overflow flaw was discovered in PHP's gd extension. A
script that could be forced to process WBMP images from an untrusted source
could result in arbitrary code execution. (CVE-2007-1001)

A buffer over-read flaw was discovered in PHP's gd extension. A script that
could be forced to write arbitrary string using a JIS font from an
untrusted source could cause the PHP interpreter to crash. (CVE-2007-0455)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-16" />
        <updated date="2007-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1285.html">CVE-2007-1285</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1286.html">CVE-2007-1286</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1583.html">CVE-2007-1583</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1711.html">CVE-2007-1711</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1718.html">CVE-2007-1718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0455.html">CVE-2007-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1001.html">CVE-2007-1001</cve>
                <bugzilla href="http://bugzilla.redhat.com/230556" id="230556">CVE-2007-1285 "Month of PHP Bugs" security issues (CVE-2007-1286 CVE-2007-1583 CVE-2007-1711 CVE-2007-1718)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/235028" id="235028">CVE-2007-1001 gd php flaws (CVE-2007-0455)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155010" comment="php-odbc is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155012" comment="php-mysql is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155002" comment="php is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155014" comment="php-pgsql is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155004" comment="php-devel is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155006" comment="php-imap is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155008" comment="php-ldap is earlier than 0:4.3.2-40.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155036" comment="php-gd is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076036" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155028" comment="php-odbc is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155033" comment="php-mysql is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155017" comment="php is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155021" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076024" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155023" comment="php-mbstring is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076022" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155029" comment="php-pgsql is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155030" comment="php-devel is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155031" comment="php-snmp is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076026" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155025" comment="php-imap is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155018" comment="php-ncurses is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076030" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155034" comment="php-pear is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076020" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155026" comment="php-domxml is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076028" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070155020" comment="php-ldap is earlier than 0:4.3.9-3.22.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070157" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0157: xorg-x11-apps and libX11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0157-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0157.html" />
          <reference source="CVE" ref_id="CVE-2007-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1667.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

An integer overflow flaw was found in the X.org XGetPixel() function.
Improper use of this function could cause an application calling it to
function improperly, possibly leading to a crash or arbitrary code
execution. (CVE-2007-1667)

Users of the X.org X11 server should upgrade to these updated packages,
which contain a backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-16" />
        <updated date="2007-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1667.html">CVE-2007-1667</cve>
                <bugzilla href="http://bugzilla.redhat.com/231694" id="231694">CVE-2007-1667 XGetPixel() integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070157004" comment="libX11-devel is earlier than 0:1.0.3-8.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070157005" comment="libX11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070157002" comment="libX11 is earlier than 0:1.0.3-8.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070157003" comment="libX11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070157006" comment="xorg-x11-apps is earlier than 0:7.1-4.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070157007" comment="xorg-x11-apps is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070158" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0158: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0158-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0158.html" />
          <reference source="CVE" ref_id="CVE-2007-1002" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1002.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string bug was found in the way Evolution parsed the category field
in a memo. If a user tried to save and then view a carefully crafted memo,
arbitrary code may be executed as the user running Evolution. (CVE-2007-1002)

This flaw did not affect the versions of Evolution shipped with Red Hat
Enterprise Linux 2.1, 3, or 4.

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Red Hat would like to thank Ulf Härnhammar of Secunia Research for
reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-03" />
        <updated date="2007-05-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1002.html">CVE-2007-1002</cve>
                <bugzilla href="http://bugzilla.redhat.com/231478" id="231478">CVE-2007-1002 evolution format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070158002" comment="evolution is earlier than 0:2.8.0-33.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070158003" comment="evolution is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070158004" comment="evolution-devel is earlier than 0:2.8.0-33.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070158005" comment="evolution-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070166" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0166: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0166-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0166.html" />
          <reference source="CVE" ref_id="CVE-2007-0243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0243.html" />
    
    <description>IBM's 1.4.2 SR8 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

A flaw in GIF image handling was found in the SUN Java Runtime Environment
that has now been reported as also affecting IBM Java 2.  An untrusted
applet or application could use this flaw to elevate its privileges and
potentially execute arbitrary code.  (CVE-2007-0243)

All users of java-1.4.2-ibm should upgrade to these updated packages, which
contain IBM's 1.4.2 SR8 Java release which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-25" />
        <updated date="2007-04-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0243.html">CVE-2007-0243</cve>
                <bugzilla href="http://bugzilla.redhat.com/236892" id="236892">CVE-2007-0243 GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237283" id="237283">CVE-2007-0243 GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237284" id="237284">CVE-2007-0243 GIF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166010" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166011" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166008" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166009" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070166012" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166013" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070167" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0167: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0167-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0167.html" />
          <reference source="CVE" ref_id="CVE-2007-0243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0243.html" />
    
    <description>IBM's 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A flaw in GIF image handling was found in the SUN Java Runtime Environment
that has now been reported as also affecting IBM Java 2. An untrusted
applet or application could use this flaw to elevate its privileges and
potentially execute arbitrary code. (CVE-2007-0243)

This update also resolves the following issues:

* The java-1.5.0-ibm-plugin sub-package conflicted with the new
java-1.5.0-sun-plugin sub-package.

* The java-1.5.0-ibm-plugin package had incorrect dependencies. The
java-1.5.0-ibm-alsa package has been merged into the java-1.5.0-ibm package
to resolve this issue.

All users of java-ibm-1.5.0 should upgrade to these packages, which contain
IBM's 1.5.0 SR4 Java release which resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-04-25" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0243.html">CVE-2007-0243</cve>
                <bugzilla href="http://bugzilla.redhat.com/236894" id="236894">CVE-2007-0243 GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237281" id="237281">CVE-2007-0243 GIF buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237290" id="237290">Installation of all Extras packages generates package conflict</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237685" id="237685">plugin does not initialize</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167012" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167013" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167010" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167011" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167008" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167009" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167014" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070167006" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.4-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167007" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070169" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0169: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0169-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0169.html" />
          <reference source="CVE" ref_id="CVE-2007-0771" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0771.html" />
          <reference source="CVE" ref_id="CVE-2007-1000" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1000.html" />
          <reference source="CVE" ref_id="CVE-2007-1388" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1388.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the IPv6 socket option handling that allowed a local user to
read arbitrary kernel memory (CVE-2007-1000, Important).

* a flaw in the IPv6 socket option handling that allowed a local user to
cause a denial of service (CVE-2007-1388, Important).

* a flaw in the utrace support that allowed a local user to cause a denial
of service (CVE-2007-0771, Important).

In addition to the security issues described above, a fix for a memory leak
in the audit subsystem and a fix for a data corruption bug on s390 systems
have been included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these erratum
packages, which are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-30" />
        <updated date="2007-04-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0771.html">CVE-2007-0771</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1000.html">CVE-2007-1000</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1388.html">CVE-2007-1388</cve>
                <bugzilla href="http://bugzilla.redhat.com/228816" id="228816">CVE-2007-0771 utrace regression / denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232255" id="232255">CVE-2007-1388 NULL pointer dereference in do_ipv6_setsockopt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232257" id="232257">CVE-2007-1000 NULL pointer hole in ipv6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233157" id="233157">Kernel memory leak in audit subsystem</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169004" comment="kernel-headers is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169002" comment="kernel is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169020" comment="kernel-doc is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169006" comment="kernel-devel is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169012" comment="kernel-kdump is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169008" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169014" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070169010" comment="kernel-xen is earlier than 0:2.6.18-8.1.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070203" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0203: unzip security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0203-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0203.html" />
          <reference source="CVE" ref_id="CVE-2005-2475" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2475.html" />
          <reference source="CVE" ref_id="CVE-2005-4667" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4667.html" />
    
    <description>The unzip utility is used to list, test, or extract files from a zip archive.

A race condition was found in Unzip. Local users could use this flaw to
modify permissions of arbitrary files via a hard link attack on a file
while it was being decompressed (CVE-2005-2475)

A buffer overflow was found in Unzip command line argument handling.
If a user could be tricked into running Unzip with a specially crafted long
file name, an attacker could execute arbitrary code with that user's
privileges. (CVE-2005-4667)

As well, this update adds support for files larger than 2GB.

All users of unzip should upgrade to these updated packages, which
contain backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2475.html">CVE-2005-2475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4667.html">CVE-2005-4667</cve>
                <bugzilla href="http://bugzilla.redhat.com/164927" id="164927">CVE-2005-2475 TOCTOU issue in unzip</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/178960" id="178960">CVE-2005-4667 unzip long filename buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/199104" id="199104">unzip has not been compiled with large file support and cannot unzip files > 2G</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230558" id="230558">unzip-5.51-8 leaves files as read-only (400)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070203002" comment="unzip is earlier than 0:5.51-9.EL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070203003" comment="unzip is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070208" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0208: w3c-libwww security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0208-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0208.html" />
          <reference source="CVE" ref_id="CVE-2005-3183" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3183.html" />
    
    <description>w3c-libwww is a general-purpose web library.

Several buffer overflow flaws in w3c-libwww were found. If a client
application that uses w3c-libwww connected to a malicious HTTP server, it
could trigger an out of bounds memory access, causing the client
application to crash (CVE-2005-3183).

This updated version of w3c-libwww also fixes an issue when computing MD5
sums on a 64 bit machine.

Users of w3c-libwww should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2007-05-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3183.html">CVE-2005-3183</cve>
                <bugzilla href="http://bugzilla.redhat.com/163664" id="163664">/usr/lib64/libmd5.so is broken.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169495" id="169495">CVE-2005-3183 Multiple bugs in libwww - one exploitable - in Library/src/HTBound.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070208002" comment="w3c-libwww is earlier than 0:5.4.0-10.1.RHEL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070208003" comment="w3c-libwww is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070208006" comment="w3c-libwww-apps is earlier than 0:5.4.0-10.1.RHEL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070208007" comment="w3c-libwww-apps is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070208004" comment="w3c-libwww-devel is earlier than 0:5.4.0-10.1.RHEL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070208005" comment="w3c-libwww-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070220" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0220: gcc security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0220-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0220.html" />
          <reference source="CVE" ref_id="CVE-2006-3619" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3619.html" />
    
    <description>The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95
GNU compilers and related support libraries.

Jürgen Weigert discovered a directory traversal flaw in fastjar. An
attacker could create a malicious JAR file which, if unpacked using
fastjar, could write to any files the victim had write access to.
(CVE-2006-3619)

These updated packages also fix several bugs, including:

* two debug information generator bugs

* two internal compiler errors

In addition to this, protoize.1 and unprotoize.1 manual pages have been
added to the package and __cxa_get_exception_ptr@@CXXABI_1.3.1 symbol has
been added into libstdc++.so.6.

For full details regarding all fixed bugs, refer to the package changelog
as well as the specified list of bug reports from bugzilla.

All users of gcc should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3619.html">CVE-2006-3619</cve>
                <bugzilla href="http://bugzilla.redhat.com/198912" id="198912">CVE-2006-3619 Directory traversal issue in fastjar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/205919" id="205919">ICE related to std::vector&lt;std::vector&lt;...> > ></bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/207277" id="207277">g++: internal compiler error: Segmentation fault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/207303" id="207303">cannot rebuild gcc when build_java is 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/214353" id="214353">gcc-3.4.6-3 didn't produce correct debug_line info for some kernel functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/218377" id="218377">g++ compile runs forever on test file with optimization and debug info</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220030" comment="gcc-g77 is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220031" comment="gcc-g77 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220024" comment="libgcj-devel is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220025" comment="libgcj-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220016" comment="libgcc is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220017" comment="libgcc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220022" comment="cpp is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220023" comment="cpp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220026" comment="gcc-gnat is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220027" comment="gcc-gnat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220012" comment="libstdc++ is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220013" comment="libstdc++ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220034" comment="libf2c is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220035" comment="libf2c is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220028" comment="gcc-c++-ppc32 is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220029" comment="gcc-c++-ppc32 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220014" comment="gcc-c++ is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220015" comment="gcc-c++ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220006" comment="gcc-objc is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220007" comment="gcc-objc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220002" comment="gcc is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220003" comment="gcc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220004" comment="gcc-java is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220005" comment="gcc-java is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220032" comment="libgcj is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220033" comment="libgcj is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220020" comment="libgnat is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220021" comment="libgnat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220008" comment="libstdc++-devel is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220009" comment="libstdc++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220018" comment="libobjc is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220019" comment="libobjc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070220010" comment="gcc-ppc32 is earlier than 0:3.4.6-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220011" comment="gcc-ppc32 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070229" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0229: gdb security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0229-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0229.html" />
          <reference source="CVE" ref_id="CVE-2006-4146" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4146.html" />
    
    <description>GDB, the GNU debugger, allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and then printing
their data.

Various buffer overflows and underflows were found in the DWARF expression
computation stack in GDB. If a user loaded an executable containing
malicious debugging information into GDB, an attacker might be able to
execute arbitrary code with the privileges of the user. (CVE-2006-4146)

This updated package also addresses the following issues:

* Fixed bogus 0x0 unwind of the thread's topmost function clone(3).

* Fixed deadlock accessing invalid address; for corrupted backtraces.

* Fixed a race which occasionally left the detached processes stopped.

* Fixed 'gcore' command for 32bit debugged processes on 64bit hosts.

* Added support for TLS 'errno' for threaded programs missing its '-debuginfo' package..

* Suggest TLS 'errno' resolving by hand if no threading was found..

* Added a fix to prevent stepping into asynchronously invoked signal handlers.

* Added a fix to avoid false warning on shared objects bfd close on Itanium.

* Fixed segmentation fault on the source display by ^X 1.

* Fixed object names keyboard completion.

* Added a fix to avoid crash of 'info threads' if stale threads exist.

* Fixed a bug where shared libraries occasionally failed to load .

* Fixed handling of exec() called by a threaded debugged program.

* Fixed rebuilding requirements of the gdb package itself on multilib systems.

* Fixed source directory pathname detection for the edit command.

All users of gdb should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4146.html">CVE-2006-4146</cve>
                <bugzilla href="http://bugzilla.redhat.com/185337" id="185337">p errno does not work when stopped at a breakpoint</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193763" id="193763">Buffer overrun in add_minsym_members</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/195429" id="195429">info threads crashes if zombie threads exist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/202682" id="202682">print call foo where foo is in library SEGV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/202689" id="202689">Cannot find user-level thread for LWP 4256: generic error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/204841" id="204841">CVE-2006-4146 GDB buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070229002" comment="gdb is earlier than 0:6.3.0.0-1.143.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070229003" comment="gdb is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070235" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0235: util-linux security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0235-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0235.html" />
          <reference source="CVE" ref_id="CVE-2006-7108" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7108.html" />
    
    <description>The util-linux package contains a collection of basic system utilities.

A flaw was found in the way the login process handled logins which did not
require authentication. Certain processes which conduct their own
authentication could allow a remote user to bypass intended access policies
which would normally be enforced by the login process. (CVE-2006-7108)

This update also fixes the following bugs:

* The partx, addpart and delpart commands were not documented.

* The "umount -l" command did not work on hung NFS mounts with cached data.

* The mount command did not mount NFS V3 share where sec=none was specified.

* The mount command did not read filesystem LABEL from unpartitioned disks.

* The mount command did not recognize labels on VFAT filesystems.

* The fdisk command did not support 4096 sector size for the "-b" option.

* The mount man page did not list option "mand" or information about
/etc/mtab limitations.

All users of util-linux should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7108.html">CVE-2006-7108</cve>
                <bugzilla href="http://bugzilla.redhat.com/169299" id="169299">umount -l should work on hung NFS mounts with cached data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177331" id="177331">CVE-2006-7108 login omits pam_acct_mgmt &amp; pam_chauthtok when authentication is skipped.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/187370" id="187370">Unable to mount NFS V3 share where sec=none is specified</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188099" id="188099">can't mount iscsi ext3 fs by label.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/197768" id="197768">man mount' does not list option 'mand'</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070235002" comment="util-linux is earlier than 0:2.12a-16.EL4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070235003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070244" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0244: busybox security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0244-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0244.html" />
          <reference source="CVE" ref_id="CVE-2006-1058" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1058.html" />
    
    <description>Busybox is a single binary which includes versions of a large number of
system commands, including a shell. This package can be useful for
recovering from certain types of system failures.

BusyBox did not use a salt when generating passwords. This made it
easier for local users to guess passwords from a stolen password file. 
(CVE-2006-1058)

All users of busybox are advised to upgrade to these updated packages,
which contain a patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1058.html">CVE-2006-1058</cve>
                <bugzilla href="http://bugzilla.redhat.com/187385" id="187385">CVE-2006-1058 BusyBox passwd command fails to generate password with salt</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070244002" comment="busybox is earlier than 0:1.00.rc1-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070244003" comment="busybox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070244004" comment="busybox-anaconda is earlier than 0:1.00.rc1-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070244005" comment="busybox-anaconda is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070245" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0245: cpio security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0245-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0245.html" />
          <reference source="CVE" ref_id="CVE-2005-4268" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4268.html" />
    
    <description>GNU cpio copies files into or out of a cpio or tar archive.

A buffer overflow was found in cpio on 64-bit platforms. By tricking a
user into adding a specially crafted large file to a cpio archive, a local
attacker may be able to exploit this flaw to execute arbitrary code with
the target user's privileges. (CVE-2005-4268)

This erratum also addresses the following bugs:

* cpio did not set exit codes appropriately.

* cpio did not create a ram disk properly.

All users of cpio are advised to upgrade to this updated package, which
contains backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4268.html">CVE-2005-4268</cve>
                <bugzilla href="http://bugzilla.redhat.com/172865" id="172865">CVE-2005-4268 cpio large filesize buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070245002" comment="cpio is earlier than 0:2.5-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070245003" comment="cpio is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070252" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0252: sendmail security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0252-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0252.html" />
          <reference source="CVE" ref_id="CVE-2006-7176" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7176.html" />
    
    <description>Sendmail is a very widely used Mail Transport Agent (MTA). MTAs deliver
mail from one machine to another. Sendmail is not a client program, but
rather a behind-the-scenes daemon that moves email over networks or the
Internet to its final destination.

The configuration of Sendmail on Red Hat Enterprise Linux was found to not
reject the "localhost.localdomain" domain name for e-mail messages that
came from external hosts. This could have allowed remote attackers to
disguise spoofed messages (CVE-2006-7176).

This updated package also fixes the following bugs:

* Infinite loop within tls read.

* Incorrect path to selinuxenabled in initscript.

* Build artifacts from sendmail-cf package.

* Missing socketmap support.

* Add support for CipherList configuration directive.

* Path for aliases file.

* Failure of shutting down sm-client.

* Allows to specify persistent queue runners.

* Missing dnl for SMART_HOST define.

* Fixes connections stay in CLOSE_WAIT.

All users of Sendmail should upgrade to these updated packages, which
contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2007-05-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7176.html">CVE-2006-7176</cve>
                <bugzilla href="http://bugzilla.redhat.com/121850" id="121850">[PATCH] infinite loop within tls_read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152282" id="152282">Incorrect path to selinuxenabled in /etc/init.d/sendmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/152955" id="152955">sendmail-cf contains rpm build artifacts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/156191" id="156191">Changelog says 'Socketmap Supported' but it's not compiled in.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166744" id="166744">aliases man page specifies incorrect location of aliases file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171838" id="171838">CVE-2006-7176 sendmail allows external mail with from address xxx@localhost.localdomain</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/172352" id="172352">Sendmail allows SSLv2 during STARTTLS, and the CipherList config option isn't supported so you can't turn it off</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200920" id="200920">shutting down sm-client fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200921" id="200921">[PATCH] method to specify persistent queue runners?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200923" id="200923">sendmail.mc missing dnl on SMART_HOST define</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070252002" comment="sendmail is earlier than 0:8.13.1-3.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070252003" comment="sendmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070252006" comment="sendmail-doc is earlier than 0:8.13.1-3.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070252007" comment="sendmail-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070252004" comment="sendmail-devel is earlier than 0:8.13.1-3.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070252005" comment="sendmail-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070252008" comment="sendmail-cf is earlier than 0:8.13.1-3.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070252009" comment="sendmail-cf is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070257" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0257: openssh security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0257-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0257.html" />
          <reference source="CVE" ref_id="CVE-2005-2666" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2666.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

OpenSSH stores hostnames, IP addresses, and keys in plaintext in the
known_hosts file.  A local attacker that has already compromised a user's
SSH account could use this information to generate a list of additional
targets that are likely to have the same password or key.  (CVE-2005-2666)

The following bugs have also been fixed in this update:

* The ssh client could abort the running connection when the server
application generated a large output at once.

* When 'X11UseLocalhost' option was set to 'no' on systems with IPv6
networking enabled, the X11 forwarding socket listened only for IPv6
connections.

* When the privilege separation was enabled in /etc/ssh/sshd_config, some
log messages in the system log were duplicated and also had timestamps from
an incorrect timezone.

All users of openssh should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2666.html">CVE-2005-2666</cve>
                <bugzilla href="http://bugzilla.redhat.com/162681" id="162681">CVE-2005-2666 openssh vulnerable to known_hosts address harvesting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/184357" id="184357">buffer_append_space: alloc not supported Error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193710" id="193710">[PATCH] audit patch for openssh missing #include "loginrec.h" in auth.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/201594" id="201594">sshd does not create ipv4 listen socket for X11 forwarding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/203671" id="203671">additional (time skewed) log entries in /var/log/secure since U4</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070257002" comment="openssh is earlier than 0:3.9p1-8.RHEL4.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070257008" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257009" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070257004" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070257006" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070257010" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257011" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070276" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0276: shadow-utils security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0276-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0276.html" />
          <reference source="CVE" ref_id="CVE-2006-1174" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1174.html" />
    
    <description>The shadow-utils package includes the necessary programs for converting
UNIX password files to the shadow password format, as well as programs for
managing user and group accounts.

A flaw was found in the useradd tool in shadow-utils. A new user's
mailbox, when created, could have random permissions for a short period.
This could allow a local attacker to read or modify the mailbox.
(CVE-2006-1174)

This update also fixes the following bugs:

* shadow-utils debuginfo package was empty.

* faillog was unusable on 64-bit systems. It checked every UID from 0 to
the max UID, which was an excessively large number on 64-bit systems.

* typo bug in login.defs file

All users of shadow-utils are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2007-05-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1174.html">CVE-2006-1174</cve>
                <bugzilla href="http://bugzilla.redhat.com/176951" id="176951">shadow-utils-debuginfo is empty</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177017" id="177017">faillog doesn't handle large UIDs well</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188263" id="188263">typo in /etc/login.defs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/193053" id="193053">CVE-2006-1174 shadow-utils mailbox creation race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070276002" comment="shadow-utils is earlier than 2:4.0.3-61.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070276003" comment="shadow-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070286" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0286: gdm security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0286-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0286.html" />
          <reference source="CVE" ref_id="CVE-2006-1057" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1057.html" />
    
    <description>Gdm (the GNOME Display Manager) is a highly configurable reimplementation
of xdm, the X Display Manager. Gdm allows you to log into your system with
the X Window System running and supports running several different X
sessions on your local machine at the same time.

Marcus Meissner discovered a race condition issue in the way Gdm modifies
the permissions on the .ICEauthority file. A local attacker could exploit
this flaw to gain privileges. Due to the nature of the flaw, however, a
successful exploitation was unlikely. (CVE-2006-1057)

This erratum also includes a bug fix to correct the pam configuration for
the audit system.

All users of gdm should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2007-05-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1057.html">CVE-2006-1057</cve>
                <bugzilla href="http://bugzilla.redhat.com/159338" id="159338">gdm update for new audit system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/188302" id="188302">CVE-2006-1057 GDM file permissions race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070286002" comment="gdm is earlier than 1:2.6.0.5-7.rhel4.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070286003" comment="gdm is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070310" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0310: openldap security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0310-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0310.html" />
          <reference source="CVE" ref_id="CVE-2006-4600" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4600.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled selfwrite access. Users with
selfwrite access were able to modify the distinguished name of any user.
(CVE-2006-4600)

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-01" />
        <updated date="2007-05-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4600.html">CVE-2006-4600</cve>
                <bugzilla href="http://bugzilla.redhat.com/205826" id="205826">CVE-2006-4600 openldap improper selfwrite access</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310008" comment="openldap-devel is earlier than 0:2.2.13-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310009" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310006" comment="openldap-clients is earlier than 0:2.2.13-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310007" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310010" comment="openldap-servers-sql is earlier than 0:2.2.13-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310011" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310012" comment="compat-openldap is earlier than 0:2.1.30-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310013" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310002" comment="openldap is earlier than 0:2.2.13-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070310004" comment="openldap-servers is earlier than 0:2.2.13-7.4E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310005" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070322" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0322: xscreensaver security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0322-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0322.html" />
          <reference source="CVE" ref_id="CVE-2007-1859" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1859.html" />
    
    <description>XScreenSaver is a collection of screensavers.

Alex Yamauchi discovered a flaw in the way XScreenSaver verifies user
passwords. When a system is using a remote directory service for login
credentials, a local attacker may be able to cause a network outage causing
XScreenSaver to crash, unlocking the screen. (CVE-2007-1859)

Users of XScreenSaver should upgrade to this updated package, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-02" />
        <updated date="2007-05-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1859.html">CVE-2007-1859</cve>
                <bugzilla href="http://bugzilla.redhat.com/237003" id="237003">CVE-2007-1859 xscreensaver authentication bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070322002" comment="xscreensaver is earlier than 1:4.10-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070322003" comment="xscreensaver is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070322005" comment="xscreensaver is earlier than 1:4.18-5.rhel4.14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070322003" comment="xscreensaver is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070323" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0323: xen security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0323.html" />
          <reference source="CVE" ref_id="CVE-2007-1320" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1320.html" />
          <reference source="CVE" ref_id="CVE-2007-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1321.html" />
          <reference source="CVE" ref_id="CVE-2007-4993" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4993.html" />
    
    <description>The Xen package contains the tools for managing the virtual machine monitor
in Red Hat Enterprise Linux virtualization.

The following security flaws are fixed in the updated Xen package:

Joris van Rantwijk found a flaw in the Pygrub utility which is used as a
boot loader for guest domains.  A malicious local administrator of a guest
domain could create a carefully crafted grub.conf file which would trigger
the execution of arbitrary code outside of that domain. (CVE-2007-4993)

Tavis Ormandy discovered a heap overflow flaw during video-to-video copy
operations in the Cirrus VGA extension code used in Xen.  A malicious local
administrator of a guest domain could potentially trigger this flaw and
execute arbitrary code outside of the domain. (CVE-2007-1320)

Tavis Ormandy discovered insufficient input validation leading to a heap
overflow in the Xen NE2000 network driver.   If the driver is in use, a
malicious local administrator of a guest domain could potentially trigger
this flaw and execute arbitrary code outside of the domain.  Xen does not
use this driver by default. (CVE-2007-1321)

Users of Xen should update to these erratum packages containing backported
patches which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-02" />
        <updated date="2007-10-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1320.html">CVE-2007-1320</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1321.html">CVE-2007-1321</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4993.html">CVE-2007-4993</cve>
                <bugzilla href="http://bugzilla.redhat.com/237342" id="237342">CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237343" id="237343">CVE-2007-1321 xen QEMU NE2000 emulation issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/302801" id="302801">CVE-2007-4993 xen guest root can escape to domain 0 through pygrub</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070323002" comment="xen is earlier than 0:3.0.3-25.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070323004" comment="xen-libs is earlier than 0:3.0.3-25.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114005" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070323006" comment="xen-devel is earlier than 0:3.0.3-25.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070114007" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070327" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0327: tomcat security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0327-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0327.html" />
          <reference source="CVE" ref_id="CVE-2005-2090" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2090.html" />
          <reference source="CVE" ref_id="CVE-2006-7195" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7195.html" />
          <reference source="CVE" ref_id="CVE-2007-1358" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1358.html" />
          <reference source="CVE" ref_id="CVE-2007-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0450.html" />
    
    <description>Tomcat is a servlet container for Java Servlet and JavaServer Pages
technologies.

Tomcat was found to accept multiple content-length headers in a
request. This could allow attackers to poison a web-cache, bypass web
application firewall protection, or conduct cross-site scripting attacks. 
(CVE-2005-2090)

Tomcat permitted various characters as path delimiters. If Tomcat was used
behind certain proxies and configured to only proxy some contexts, an
attacker could construct an HTTP request to work around the context
restriction and potentially access non-proxied content. (CVE-2007-0450)

The implict-objects.jsp file distributed in the examples webapp displayed a
number of unfiltered header values. If the JSP examples were accessible,
this flaw could allow a remote attacker to perform cross-site scripting
attacks. (CVE-2006-7195)

Users should upgrade to these erratum packages which contain an update to
Tomcat that resolves these issues.  Updated jakarta-commons-modeler
packages are also included which correct a bug when used with Tomcat 5.5.23.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2090.html">CVE-2005-2090</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7195.html">CVE-2006-7195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1358.html">CVE-2007-1358</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0450.html">CVE-2007-0450</cve>
                <bugzilla href="http://bugzilla.redhat.com/237089" id="237089">CVE-2005-2090 multiple tomcat issues (CVE-2007-0450 CVE-2006-7195)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327002" comment="redhat-rpm-config is earlier than 0:8.0.45-17.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327003" comment="redhat-rpm-config is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327016" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327017" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327006" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327007" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327014" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327015" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327012" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327013" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327008" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327009" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327010" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327011" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327024" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327025" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327018" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327019" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327022" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327023" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327020" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327021" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327004" comment="tomcat5 is earlier than 0:5.5.23-0jpp.1.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327005" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327028" comment="jakarta-commons-modeler-javadoc is earlier than 0:1.1-8jpp.1.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327029" comment="jakarta-commons-modeler-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070327026" comment="jakarta-commons-modeler is earlier than 0:1.1-8jpp.1.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327027" comment="jakarta-commons-modeler is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070336" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0336: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0336-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0336.html" />
          <reference source="CVE" ref_id="CVE-2007-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2138.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw was found in the way PostgreSQL allows authenticated users to
execute security-definer functions.  It was possible for an unprivileged
user to execute arbitrary code with the privileges of the security-definer
function. (CVE-2007-2138)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 8.1.9, 7.4.17, and 7.3.19 which corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-08" />
        <updated date="2007-05-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2138.html">CVE-2007-2138</cve>
                <bugzilla href="http://bugzilla.redhat.com/237680" id="237680">CVE-2007-2138 PostgreSQL security-definer function privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336014" comment="postgresql-docs is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068005" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336018" comment="postgresql-devel is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068009" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336010" comment="postgresql-test is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068021" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336006" comment="postgresql-contrib is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068013" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336004" comment="postgresql-libs is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068011" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336012" comment="postgresql-tcl is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068007" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336002" comment="postgresql is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336020" comment="postgresql-server is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068019" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336016" comment="postgresql-pl is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068017" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336008" comment="postgresql-python is earlier than 0:8.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070068015" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336031" comment="rh-postgresql-docs is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064009" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336025" comment="rh-postgresql-jdbc is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064005" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336041" comment="rh-postgresql-contrib is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064017" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336023" comment="rh-postgresql is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336039" comment="rh-postgresql-python is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336035" comment="rh-postgresql-devel is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064013" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336029" comment="rh-postgresql-pl is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336043" comment="rh-postgresql-test is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064007" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336037" comment="rh-postgresql-tcl is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064023" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336033" comment="rh-postgresql-libs is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064011" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336027" comment="rh-postgresql-server is earlier than 0:7.3.19-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064021" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336058" comment="postgresql-docs is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064046" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336052" comment="postgresql-jdbc is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064032" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336048" comment="postgresql-devel is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064036" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336056" comment="postgresql-test is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064042" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336050" comment="postgresql-contrib is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064038" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336062" comment="postgresql-libs is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064030" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336064" comment="postgresql-tcl is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064040" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336046" comment="postgresql is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064026" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336066" comment="postgresql-pl is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064028" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336060" comment="postgresql-server is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064034" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070336054" comment="postgresql-python is earlier than 0:7.4.17-1.RHEL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070064044" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070338" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0338: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0338-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0338.html" />
          <reference source="CVE" ref_id="CVE-2007-2028" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2028.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A memory leak flaw was found in the way FreeRADIUS parses certain
authentication requests. A remote attacker could send a specially crafted
authentication request which could cause FreeRADIUS to leak a small amount
of memory. If enough of these requests are sent, the FreeRADIUS daemon
would consume a vast quantity of system memory leading to a possible denial
of service.   (CVE-2007-2028)

Users of FreeRADIUS should update to these erratum packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-10" />
        <updated date="2007-05-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2028.html">CVE-2007-2028</cve>
                <bugzilla href="http://bugzilla.redhat.com/236247" id="236247">CVE-2007-2028 Freeradius EAP-TTLS denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338004" comment="freeradius-mysql is earlier than 0:1.1.3-1.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338005" comment="freeradius-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338008" comment="freeradius-postgresql is earlier than 0:1.1.3-1.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338009" comment="freeradius-postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338006" comment="freeradius-unixODBC is earlier than 0:1.1.3-1.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338007" comment="freeradius-unixODBC is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338002" comment="freeradius is earlier than 0:1.1.3-1.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338003" comment="freeradius is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338017" comment="freeradius-mysql is earlier than 0:1.0.1-2.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338018" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338015" comment="freeradius-postgresql is earlier than 0:1.0.1-2.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338016" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338013" comment="freeradius-unixODBC is earlier than 0:1.0.1-2.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338014" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338011" comment="freeradius is earlier than 0:1.0.1-2.RHEL3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338012" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338022" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338018" comment="freeradius-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338021" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338016" comment="freeradius-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338023" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338014" comment="freeradius-unixODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070338020" comment="freeradius is earlier than 0:1.0.1-3.RHEL4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070338012" comment="freeradius is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070342" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0342: ipsec-tools security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0342-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0342.html" />
          <reference source="CVE" ref_id="CVE-2007-1841" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1841.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon. It was
possible for a remote attacker, with knowledge of an existing ipsec tunnel,
to terminate the ipsec connection between two machines. (CVE-2007-1841)

Users of ipsec-tools should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-17" />
        <updated date="2007-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1841.html">CVE-2007-1841</cve>
                <bugzilla href="http://bugzilla.redhat.com/235388" id="235388">CVE-2007-1841 ipsec-tools racoon DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070342002" comment="ipsec-tools is earlier than 0:0.6.5-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070342003" comment="ipsec-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070343" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0343: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0343-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0343.html" />
          <reference source="CVE" ref_id="CVE-2007-2356" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2356.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Marsu discovered a stack overflow bug in The GIMP RAS file loader.  An
attacker could create a carefully crafted file that could cause The GIMP to
crash or possibly execute arbitrary code if the file was opened by a
victim.  (CVE-2007-2356)

For users of Red Hat Enterprise Linux 5, the previous GIMP packages had a
bug that concerned the execution order in which the symbolic links to
externally packaged GIMP plugins are installed and removed, causing the
symbolic links to vanish when the package is updated.

Users of The GIMP should update to these erratum packages which contain a
backported fix to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-21" />
        <updated date="2007-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2356.html">CVE-2007-2356</cve>
                <bugzilla href="http://bugzilla.redhat.com/238420" id="238420">CVE-2007-2356 Stack overflow in gimp's sunras plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238993" id="238993">gimp removes symlinks to plugins of other packages when updated</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343006" comment="gimp-libs is earlier than 2:2.2.13-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343007" comment="gimp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343004" comment="gimp-devel is earlier than 2:2.2.13-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343005" comment="gimp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343002" comment="gimp is earlier than 2:2.2.13-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343003" comment="gimp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343011" comment="gimp-perl is earlier than 1:1.2.3-20.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343012" comment="gimp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343013" comment="gimp-devel is earlier than 1:1.2.3-20.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343014" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343009" comment="gimp is earlier than 1:1.2.3-20.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343010" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343017" comment="gimp-devel is earlier than 1:2.0.5-6.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343014" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070343016" comment="gimp is earlier than 1:2.0.5-6.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343010" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070344" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0344: evolution-data-server security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0344.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
    
    <description>The evolution-data-server package provides a unified backend for programs
that work with contacts, tasks, and calendar information.

A flaw was found in the way evolution-data-server processed certain APOP
authentication requests. By sending certain responses when
evolution-data-server attempted to authenticate against an APOP server, a
remote attacker could potentially acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

All users of evolution-data-server should upgrade to these updated
packages, which contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
                <bugzilla href="http://bugzilla.redhat.com/235289" id="235289">CVE-2007-1558 Evolution APOP information disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070344002" comment="evolution-data-server is earlier than 0:1.8.0-15.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070344003" comment="evolution-data-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070344004" comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070344005" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070345" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0345: vixie-cron security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0345-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0345.html" />
          <reference source="CVE" ref_id="CVE-2007-1856" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1856.html" />
    
    <description>The vixie-cron package contains the Vixie version of cron. Cron is a
standard UNIX daemon that runs specified programs at scheduled times.

Raphael Marichez discovered a denial of service bug in the way vixie-cron
verifies crontab file integrity. A local user with the ability to create a
hardlink to /etc/crontab can prevent vixie-cron from executing certain
system  cron jobs. (CVE-2007-1856)

All users of vixie-cron should upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-17" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1856.html">CVE-2007-1856</cve>
                <bugzilla href="http://bugzilla.redhat.com/223662" id="223662">crond failed "Days of week" after a few hours on 1st/Jan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/235880" id="235880">CVE-2007-1856 crontab denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345002" comment="vixie-cron is earlier than 4:4.1-70.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345003" comment="vixie-cron is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345005" comment="vixie-cron is earlier than 0:4.1-19.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345006" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345008" comment="vixie-cron is earlier than 4:4.1-47.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070345006" comment="vixie-cron is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070346" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0346: vim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0346.html" />
          <reference source="CVE" ref_id="CVE-2007-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2438.html" />
    
    <description>VIM (VIsual editor iMproved) is a version of the vi editor.

An arbitrary command execution flaw was found in the way VIM processes
modelines.  If a user with modelines enabled opened a text file containing
a carefully crafted modeline, arbitrary commands could be executed as the user
running VIM. (CVE-2007-2438)

Users of VIM are advised to upgrade to these updated packages, which
resolve this issue.

Please note: this issue did not affect VIM as distributed with Red Hat
Enterprise Linux 2.1, 3, or 4.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-09" />
        <updated date="2007-05-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2438.html">CVE-2007-2438</cve>
                <bugzilla href="http://bugzilla.redhat.com/238259" id="238259">CVE-2007-2438 vim-7 modeline security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070346004" comment="vim-minimal is earlier than 2:7.0.109-3.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070346005" comment="vim-minimal is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070346002" comment="vim is earlier than 2:7.0.109-3.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070346003" comment="vim is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070346008" comment="vim-X11 is earlier than 2:7.0.109-3.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070346009" comment="vim-X11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070346010" comment="vim-common is earlier than 2:7.0.109-3.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070346011" comment="vim-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070346006" comment="vim-enhanced is earlier than 2:7.0.109-3.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070346007" comment="vim-enhanced is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070347" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0347: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0347-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0347.html" />
          <reference source="CVE" ref_id="CVE-2007-1496" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1496.html" />
          <reference source="CVE" ref_id="CVE-2007-1497" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1497.html" />
          <reference source="CVE" ref_id="CVE-2007-1592" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1592.html" />
          <reference source="CVE" ref_id="CVE-2007-1861" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1861.html" />
          <reference source="CVE" ref_id="CVE-2007-2172" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2172.html" />
          <reference source="CVE" ref_id="CVE-2007-2242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2242.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the handling of IPv6 type 0 routing headers that allowed remote
users to cause a denial of service that led to a network amplification
between two routers (CVE-2007-2242, Important).

* a flaw in the nfnetlink_log netfilter module that allowed a local user to
cause a denial of service (CVE-2007-1496, Important).

* a flaw in the flow list of listening IPv6 sockets that allowed a local
user to cause a denial of service (CVE-2007-1592, Important).

* a flaw in the handling of netlink messages that allowed a local user to
cause a denial of service (infinite recursion) (CVE-2007-1861, Important).

* a flaw in the IPv4 forwarding base that allowed a local user to cause an
out-of-bounds access (CVE-2007-2172, Important).

* a flaw in the nf_conntrack netfilter module for IPv6 that allowed remote
users to bypass certain netfilter rules using IPv6 fragments
(CVE-2007-1497, Moderate).

In addition to the security issues described above, fixes for the following
have been included:

* a regression in ipv6 routing.

* an error in memory initialization that caused gdb to output inaccurate
backtraces on ia64.

* the nmi watchdog timeout was updated from 5 to 30 seconds.

* a flaw in distributed lock management that could result in errors during
virtual machine migration.

* an omitted include in kernel-headers that led to compile failures for
some packages.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-16" />
        <updated date="2007-05-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1496.html">CVE-2007-1496</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1497.html">CVE-2007-1497</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1592.html">CVE-2007-1592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1861.html">CVE-2007-1861</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2172.html">CVE-2007-2172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2242.html">CVE-2007-2242</cve>
                <bugzilla href="http://bugzilla.redhat.com/238046" id="238046">oops and panics bringing up/down interfaces on 128p Altix, 8 interfaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238731" id="238731">dlm locking error from gfs dio/aio during virt machine migration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238749" id="238749">The patch "xen: Add PACKET_AUXDATA cmsg" cause /usr/include/linux/if_packet.h broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238944" id="238944">CVE-2007-1592 IPv6 oops triggerable by any user</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238946" id="238946">CVE-2007-1496 Various NULL pointer dereferences in netfilter code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238947" id="238947">CVE-2007-1497 IPv6 fragments bypass in nf_conntrack netfilter code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238948" id="238948">CVE-2007-2172 fib_semantics.c out of bounds access vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238949" id="238949">CVE-2007-2242 IPv6 routing headers issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238960" id="238960">CVE-2007-1861 infinite recursion in netlink</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347004" comment="kernel-headers is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347002" comment="kernel is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347020" comment="kernel-doc is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347006" comment="kernel-devel is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347014" comment="kernel-kdump is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347010" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347012" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070347008" comment="kernel-xen is earlier than 0:2.6.18-8.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070348" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0348: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0348-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0348.html" />
          <reference source="CVE" ref_id="CVE-2007-1864" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1864.html" />
          <reference source="CVE" ref_id="CVE-2007-2509" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2509.html" />
          <reference source="CVE" ref_id="CVE-2007-2510" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2510.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A heap buffer overflow flaw was found in the PHP 'xmlrpc' extension.  A
PHP script which implements an XML-RPC server using this extension
could allow a remote attacker to execute arbitrary code as the 'apache'
user.  Note that this flaw does not affect PHP applications using the
pure-PHP XML_RPC class provided in /usr/share/pear. (CVE-2007-1864)

A flaw was found in the PHP 'ftp' extension.  If a PHP script used this
extension to provide access to a private FTP server, and passed untrusted
script input directly to any function provided by this extension, a remote
attacker would be able to send arbitrary FTP commands to the server. 
(CVE-2007-2509)

A buffer overflow flaw was found in the PHP 'soap' extension, regarding the
handling of an HTTP redirect response when using the SOAP client provided
by this extension with an untrusted SOAP server.  No mechanism to trigger
this flaw remotely is known.  (CVE-2007-2510)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-08" />
        <updated date="2007-05-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1864.html">CVE-2007-1864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2509.html">CVE-2007-2509</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2510.html">CVE-2007-2510</cve>
                <bugzilla href="http://bugzilla.redhat.com/239015" id="239015">CVE-2007-1864 various PHP security issues (CVE-2007-2509 CVE-2007-2510)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348038" comment="php-common is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082009" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348034" comment="php-gd is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082035" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348030" comment="php-odbc is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082037" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348016" comment="php-soap is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082015" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348036" comment="php-mysql is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082025" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348002" comment="php is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348032" comment="php-xmlrpc is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082005" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348028" comment="php-cli is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082019" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348024" comment="php-mbstring is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082033" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348020" comment="php-pgsql is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082023" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348018" comment="php-xml is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082039" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348014" comment="php-devel is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082021" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348010" comment="php-dba is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082007" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348022" comment="php-bcmath is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082011" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348012" comment="php-imap is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082031" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348006" comment="php-snmp is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082017" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348004" comment="php-ncurses is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082013" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348026" comment="php-pdo is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082027" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070348008" comment="php-ldap is earlier than 0:5.1.6-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082029" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070349" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0349: php security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0349-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0349.html" />
          <reference source="CVE" ref_id="CVE-2007-1864" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1864.html" />
          <reference source="CVE" ref_id="CVE-2007-2509" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2509.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server. 

A heap buffer overflow flaw was found in the PHP 'xmlrpc' extension. A
PHP script which implements an XML-RPC server using this extension could
allow a remote attacker to execute arbitrary code as the 'apache' user.
Note that this flaw does not affect PHP applications using the pure-PHP
XML_RPC class provided in /usr/share/pear. (CVE-2007-1864)

A flaw was found in the PHP 'ftp' extension. If a PHP script used this
extension to provide access to a private FTP server, and passed untrusted
script input directly to any function provided by this extension, a remote
attacker would be able to send arbitrary FTP commands to the server.
(CVE-2007-2509)

Users of PHP should upgrade to these updated packages which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-09" />
        <updated date="2007-05-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1864.html">CVE-2007-1864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2509.html">CVE-2007-2509</cve>
                <bugzilla href="http://bugzilla.redhat.com/239017" id="239017">CVE-2007-1864 various PHP security issues (CVE-2007-2509)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349026" comment="php-gd is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076036" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349016" comment="php-odbc is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349004" comment="php-mysql is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349002" comment="php is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349028" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076024" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349010" comment="php-mbstring is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076022" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349020" comment="php-pgsql is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349006" comment="php-devel is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349018" comment="php-imap is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349014" comment="php-snmp is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076026" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349008" comment="php-ncurses is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076030" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349022" comment="php-pear is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076020" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349024" comment="php-ldap is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070349012" comment="php-domxml is earlier than 0:4.3.9-3.22.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076028" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070353" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0353: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0353-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0353.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processed certain APOP authentication
requests. A remote attacker could potentially acquire certain portions of a
user's authentication credentials by sending certain responses when
evolution-data-server attempted to authenticate against an APOP server.
(CVE-2007-1558)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-17" />
        <updated date="2007-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
                <bugzilla href="http://bugzilla.redhat.com/238565" id="238565">CVE-2007-1558 Evolution APOP information disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070353002" comment="evolution is earlier than 0:1.4.5-20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070353004" comment="evolution-devel is earlier than 0:1.4.5-20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070353007" comment="evolution is earlier than 0:2.0.2-35.0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070353008" comment="evolution-devel is earlier than 0:2.0.2-35.0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070354" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0354: samba security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0354-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0354.html" />
          <reference source="CVE" ref_id="CVE-2007-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2446.html" />
          <reference source="CVE" ref_id="CVE-2007-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2447.html" />
    
    <description>Samba provides file and printer sharing services to SMB/CIFS clients.

Various bugs were found in NDR parsing, used to decode MS-RPC requests in
Samba.  A remote attacker could have sent carefully crafted requests
causing a heap overflow, which may have led to the ability to execute
arbitrary code on the server.  (CVE-2007-2446)

Unescaped user input parameters were being passed as arguments to /bin/sh.
A remote, authenticated, user could have triggered this flaw and executed
arbitrary code on the server.  Additionally, on Red Hat Enterprise Linux 5
only, this flaw could be triggered by a remote unauthenticated user if
Samba was configured to use the non-default "username map script" option. 
(CVE-2007-2447)

Users of Samba should upgrade to these packages, which contain backported
patches to correct these issues.  After upgrading, Samba should be
restarted using "service smb restart"

On Red Hat Enterprise Linux 5 the impact of these issues is reduced as
Samba is constrained by the default SELinux "targeted" policy.

Red Hat would like to thank the Samba developers, TippingPoint, and
iDefense for reporting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-05-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2446.html">CVE-2007-2446</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2447.html">CVE-2007-2447</cve>
                <bugzilla href="http://bugzilla.redhat.com/239429" id="239429">CVE-2007-2446 samba heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239774" id="239774">CVE-2007-2447 samba code injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354008" comment="samba-client is earlier than 0:3.0.23c-2.el5.2.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354006" comment="samba-common is earlier than 0:3.0.23c-2.el5.2.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061005" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354002" comment="samba is earlier than 0:3.0.23c-2.el5.2.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354004" comment="samba-swat is earlier than 0:3.0.23c-2.el5.2.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061007" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354013" comment="samba-client is earlier than 0:3.0.9-1.3E.13.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354015" comment="samba-common is earlier than 0:3.0.9-1.3E.13.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354011" comment="samba is earlier than 0:3.0.9-1.3E.13.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354017" comment="samba-swat is earlier than 0:3.0.9-1.3E.13.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354022" comment="samba-client is earlier than 0:3.0.10-1.4E.12.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354023" comment="samba-common is earlier than 0:3.0.10-1.4E.12.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354020" comment="samba is earlier than 0:3.0.10-1.4E.12.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070354021" comment="samba-swat is earlier than 0:3.0.10-1.4E.12.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070356" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0356: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0356-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0356.html" />
          <reference source="CVE" ref_id="CVE-2006-5793" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5793.html" />
          <reference source="CVE" ref_id="CVE-2007-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2445.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was found in the handling of malformed images in libpng. An attacker
could create a carefully crafted PNG image file in such a way that it could
cause an application linked with libpng to crash when the file was
manipulated.  (CVE-2007-2445)

A flaw was found in the sPLT chunk handling code in libpng. An attacker
could create a carefully crafted PNG image file in such a way that it could
cause an application linked with libpng to crash when the file was opened. 
(CVE-2006-5793)

Users of libpng should update to these updated packages which contain
backported patches to correct these issues.

Red Hat would like to thank Glenn Randers-Pehrson, Mats Palmgren, and Tavis
Ormandy for supplying details and patches for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-17" />
        <updated date="2007-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5793.html">CVE-2006-5793</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2445.html">CVE-2007-2445</cve>
                <bugzilla href="http://bugzilla.redhat.com/215405" id="215405">CVE-2006-5793 libpng DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239425" id="239425">CVE-2007-2445 libpng png_handle_tRNS flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356002" comment="libpng is earlier than 2:1.2.10-7.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356003" comment="libpng is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356004" comment="libpng-devel is earlier than 2:1.2.10-7.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356005" comment="libpng-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356007" comment="libpng is earlier than 2:1.2.2-27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356009" comment="libpng-devel is earlier than 2:1.2.2-27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356013" comment="libpng10-devel is earlier than 0:1.0.13-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356011" comment="libpng10 is earlier than 0:1.0.13-17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356016" comment="libpng is earlier than 2:1.2.7-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356017" comment="libpng-devel is earlier than 2:1.2.7-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356019" comment="libpng10-devel is earlier than 0:1.0.16-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070356018" comment="libpng10 is earlier than 0:1.0.16-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070358" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0358: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0358-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0358.html" />
          <reference source="CVE" ref_id="CVE-2007-1262" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1262.html" />
          <reference source="CVE" ref_id="CVE-2007-2589" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2589.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP4. 

Several HTML filtering bugs were discovered in SquirrelMail.  An attacker
could inject arbitrary JavaScript leading to cross-site scripting attacks
by sending an e-mail viewed by a user within SquirrelMail. 
(CVE-2007-1262)

Squirrelmail did not sufficiently check arguments to IMG tags in HTML
e-mail messages. This could be exploited by an attacker by sending
arbitrary e-mail messages on behalf of a squirrelmail user tricked into opening
a maliciously crafted HTML e-mail message.  (CVE-2007-2589)

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-17" />
        <updated date="2007-05-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1262.html">CVE-2007-1262</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2589.html">CVE-2007-2589</cve>
                <bugzilla href="http://bugzilla.redhat.com/239647" id="239647">CVE-2007-1262 XSS through HTML message in squirrelmail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239828" id="239828">CVE-2007-2589 CSRF through HTML message in squirrelmail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070358002" comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070358003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070358005" comment="squirrelmail is earlier than 0:1.4.8-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070358008" comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070368" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0368: tcpdump security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0368-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0368.html" />
          <reference source="CVE" ref_id="CVE-2007-1218" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1218.html" />
          <reference source="CVE" ref_id="CVE-2007-3798" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3798.html" />
    
    <description>Tcpdump is a command line tool for monitoring network traffic.

Moritz Jodeit discovered a denial of service bug in the tcpdump IEEE 802.11
processing code. If a certain link type was explicitly specified, an
attacker could inject a carefully crafted frame onto the IEEE 802.11
network that could crash a running tcpdump session. (CVE-2007-1218)

An integer overflow flaw was found in tcpdump's BGP processing code. An
attacker could execute arbitrary code with the privilege of the pcap user
by injecting a crafted frame onto the network. (CVE-2007-3798)

In addition, the following bugs have been addressed:

* The arpwatch service initialization script would exit prematurely,
returning an incorrect successful exit status and preventing the status
command from running in case networking is not available.

* Tcpdump would not drop root privileges completely when launched with the
-C option. This might have been abused by an attacker to gain root
privileges in case a security problem was found in tcpdump. Users of
tcpdump are encouraged to specify meaningful arguments to the -Z option in
case they want tcpdump to write files with privileges other than of the
pcap user.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1218.html">CVE-2007-1218</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3798.html">CVE-2007-3798</cve>
                <bugzilla href="http://bugzilla.redhat.com/232347" id="232347">CVE-2007-1218 tcpdump denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237779" id="237779">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241677" id="241677">tcpdump -Z -C should drop root privileges completely</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250275" id="250275">CVE-2007-3798 tcpdump BGP integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070368006" comment="libpcap is earlier than 14:0.9.4-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070368007" comment="libpcap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070368002" comment="tcpdump is earlier than 14:3.9.4-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070368003" comment="tcpdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070368008" comment="libpcap-devel is earlier than 14:0.9.4-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070368009" comment="libpcap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070368004" comment="arpwatch is earlier than 14:2.1a13-18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070368005" comment="arpwatch is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070376" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0376: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0376.html" />
          <reference source="CVE" ref_id="CVE-2006-7203" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7203.html" />
          <reference source="CVE" ref_id="CVE-2007-1353" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1353.html" />
          <reference source="CVE" ref_id="CVE-2007-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2453.html" />
          <reference source="CVE" ref_id="CVE-2007-2525" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2525.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the mount handling routine for 64-bit systems that allowed a
local user to cause denial of service (CVE-2006-7203, Important).

* a flaw in the PPP over Ethernet implementation that allowed a remote user
to cause a denial of service (CVE-2007-2525, Important).

* a flaw in the Bluetooth subsystem that allowed a local user to trigger an
information leak (CVE-2007-1353, Low).

* a bug in the random number generator that prevented the manual seeding of
the entropy pool (CVE-2007-2453, Low).

In addition to the security issues described above, fixes for the following
have been included:

* a race condition between ext3_link/unlink that could create an orphan
inode list corruption.

* a bug in the e1000 driver that could lead to a watchdog timeout panic.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-14" />
        <updated date="2007-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7203.html">CVE-2006-7203</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1353.html">CVE-2007-1353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2453.html">CVE-2007-2453</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2525.html">CVE-2007-2525</cve>
                <bugzilla href="http://bugzilla.redhat.com/238048" id="238048">watchdog timeout panic in e1000 driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240456" id="240456">CVE-2006-7203 oops in compat_sys_mount() when data pointer is NULL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241862" id="241862">CVE-2007-1353 Bluetooth setsockopt() information leaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241863" id="241863">CVE-2007-2525 PPPoE socket PPPIOCGCHAN denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241888" id="241888">CVE-2007-2453 Slightly degraded pool mixing for entropy extraction</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376004" comment="kernel-headers is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376002" comment="kernel is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376020" comment="kernel-doc is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376018" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376008" comment="kernel-devel is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376014" comment="kernel-kdump is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376006" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376016" comment="kernel-PAE is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376012" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070376010" comment="kernel-xen is earlier than 0:2.6.18-8.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070384" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0384: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0384.html" />
          <reference source="CVE" ref_id="CVE-2007-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2442.html" />
          <reference source="CVE" ref_id="CVE-2007-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2443.html" />
          <reference source="CVE" ref_id="CVE-2007-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2798.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC. kadmind is the KADM5 administration
server.

David Coffey discovered an uninitialized pointer free flaw in the RPC
library used by kadmind. A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash or potentially
execute arbitrary code as root. (CVE-2007-2442)

David Coffey also discovered an overflow flaw in the RPC library used by
kadmind. On Red Hat Enterprise Linux, exploitation of this flaw is limited
to a denial of service. A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-2443)

A stack buffer overflow flaw was found in kadmind. An authenticated
attacker who can access kadmind could trigger this flaw and potentially
execute arbitrary code on the Kerberos server. (CVE-2007-2798)

For Red Hat Enterprise Linux 2.1, several portability bugs which would lead
to unexpected crashes on the ia64 platform have also been fixed.

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-26" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2442.html">CVE-2007-2442</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2443.html">CVE-2007-2443</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2798.html">CVE-2007-2798</cve>
                <bugzilla href="http://bugzilla.redhat.com/241590" id="241590">kadmin core dumps on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245547" id="245547">CVE-2007-2442 krb5 RPC library unitialized pointer free</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245548" id="245548">CVE-2007-2443 krb5 RPC library stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245549" id="245549">CVE-2007-2798 krb5 kadmind buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070384008" comment="krb5-libs is earlier than 0:1.2.7-66" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095016" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070384006" comment="krb5-devel is earlier than 0:1.2.7-66" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095020" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070384004" comment="krb5-server is earlier than 0:1.2.7-66" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095022" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070384002" comment="krb5 is earlier than 0:1.2.7-66" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095014" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070384010" comment="krb5-workstation is earlier than 0:1.2.7-66" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095018" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070385" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0385: fetchmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0385-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0385.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
    
    <description>Fetchmail is a remote mail retrieval and forwarding utility intended
for use over on-demand TCP/IP links, like SLIP or PPP connections.

A flaw was found in the way fetchmail processed certain APOP authentication
requests. By sending certain responses when fetchmail attempted to
authenticate against an APOP server, a remote attacker could potentially
acquire certain portions of a user's authentication credentials.
(CVE-2007-1558)

All users of fetchmail should upgrade to this updated package, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2007-06-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
                <bugzilla href="http://bugzilla.redhat.com/241191" id="241191">CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070385002" comment="fetchmail is earlier than 0:6.3.6-1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070385003" comment="fetchmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070385005" comment="fetchmail is earlier than 0:6.2.0-3.el3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070385008" comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070386" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0386: mutt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0386-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0386.html" />
          <reference source="CVE" ref_id="CVE-2006-5297" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5297.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
          <reference source="CVE" ref_id="CVE-2007-2683" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2683.html" />
    
    <description>Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt used temporary files on NFS file systems.
Due to an implementation issue in the NFS protocol, Mutt was not able to
exclusively open a new file.  A local attacker could conduct a
time-dependent attack and possibly gain access to e-mail attachments opened
by a victim. (CVE-2006-5297)

A flaw was found in the way Mutt processed certain APOP authentication
requests. By sending certain responses when mutt attempted to authenticate
against an APOP server, a remote attacker could potentially acquire certain
portions of a user's authentication credentials. (CVE-2007-1558)

A flaw was found in the way Mutt handled certain characters in gecos fields
which could lead to a buffer overflow.  The gecos field is an entry in the
password database typically used to record general information about the
user.  A local attacker could give themselves a carefully crafted "Real
Name" which could execute arbitrary code if a victim uses Mutt and expands
the attackers alias.  (CVE-2007-2683)

All users of mutt should upgrade to this updated package, which
contains a backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-04" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5297.html">CVE-2006-5297</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2683.html">CVE-2007-2683</cve>
                <bugzilla href="http://bugzilla.redhat.com/211085" id="211085">CVE-2006-5297 Multiple mutt tempfile race conditions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239890" id="239890">CVE-2007-2683 Buffer overflow in mutt's gecos structure handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241191" id="241191">CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386002" comment="mutt is earlier than 5:1.4.2.2-3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386003" comment="mutt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386005" comment="mutt is earlier than 5:1.4.1-5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386006" comment="mutt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386008" comment="mutt is earlier than 5:1.4.1-12.0.3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070386006" comment="mutt is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070387" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0387: tcpdump security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0387-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0387.html" />
          <reference source="CVE" ref_id="CVE-2007-1218" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1218.html" />
          <reference source="CVE" ref_id="CVE-2007-3798" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3798.html" />
    
    <description>Tcpdump is a command line tool for monitoring network traffic.

Moritz Jodeit discovered a denial of service bug in the tcpdump IEEE
802.11 processing code. An attacker could inject a carefully crafted frame
onto the IEEE 802.11 network that could crash a running tcpdump session if
a certain link type was explicitly specified. (CVE-2007-1218)

An integer overflow flaw was found in tcpdump's BGP processing code. An
attacker could execute arbitrary code with the privilege of the pcap user
by injecting a crafted frame onto the network. (CVE-2007-3798)

In addition, the following bugs have been addressed: 

* if called with -C and -W switches, tcpdump would create the first
savefile with the privileges of the user that executed tcpdump (usually
root), rather than with ones of the pcap user.  This could result in the
inability to save the complete traffic log file properly without the
immediate notice of the user running tcpdump.

* the arpwatch service initialization script would exit prematurely,
returning a successful exit status incorrectly and preventing the status
command from running in case networking is not available.

Users of tcpdump are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1218.html">CVE-2007-1218</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3798.html">CVE-2007-3798</cve>
                <bugzilla href="http://bugzilla.redhat.com/214377" id="214377">tcpdump gives 'permission denied' at 2nd file when dumping to >1 file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232519" id="232519">CVE-2007-1218 tcpdump denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250275" id="250275">CVE-2007-3798 tcpdump BGP integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070387006" comment="libpcap is earlier than 14:0.8.3-12.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070387007" comment="libpcap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070387002" comment="tcpdump is earlier than 14:3.8.2-12.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070387003" comment="tcpdump is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070387004" comment="arpwatch is earlier than 14:2.1a13-12.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070387005" comment="arpwatch is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070389" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0389: quagga security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0389-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0389.html" />
          <reference source="CVE" ref_id="CVE-2007-1995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1995.html" />
    
    <description>Quagga is a TCP/IP based routing software suite.

An out of bounds memory read flaw was discovered in Quagga's bgpd.  A
configured peer of bgpd could cause Quagga to crash, leading to a denial of
service (CVE-2007-1995).

All users of Quagga should upgrade to this updated package, which
contains a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1995.html">CVE-2007-1995</cve>
                <bugzilla href="http://bugzilla.redhat.com/240478" id="240478">CVE-2007-1995 Quagga bgpd DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389006" comment="quagga-devel is earlier than 0:0.98.6-2.1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389007" comment="quagga-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389004" comment="quagga-contrib is earlier than 0:0.98.6-2.1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389005" comment="quagga-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389002" comment="quagga is earlier than 0:0.98.6-2.1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389003" comment="quagga is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389011" comment="quagga-devel is earlier than 0:0.96.2-12.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389012" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389013" comment="quagga-contrib is earlier than 0:0.96.2-12.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389014" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389009" comment="quagga is earlier than 0:0.96.2-12.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389010" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389017" comment="quagga-devel is earlier than 0:0.98.3-2.4.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389012" comment="quagga-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389018" comment="quagga-contrib is earlier than 0:0.98.3-2.4.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389014" comment="quagga-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070389016" comment="quagga is earlier than 0:0.98.3-2.4.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070389010" comment="quagga is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070391" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0391: file security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0391-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0391.html" />
          <reference source="CVE" ref_id="CVE-2007-2799" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2799.html" />
    
    <description>The file command is used to identify a particular file according to the
type of data contained by the file.

The fix for CVE-2007-1536 introduced a new integer underflow flaw in the
file utility. An attacker could create a carefully crafted file which, if
examined by a victim using the file utility, could lead to arbitrary code
execution. (CVE-2007-2799)

This issue did not affect the version of the file utility distributed with
Red Hat Enterprise Linux 2.1 or 3.

Users should upgrade to this erratum package, which contain a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2799.html">CVE-2007-2799</cve>
                <bugzilla href="http://bugzilla.redhat.com/241022" id="241022">CVE-2007-2799 file integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241026" id="241026">CVE-2007-2799 file integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241027" id="241027">CVE-2007-2799 file integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070391002" comment="file is earlier than 0:4.17-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124003" comment="file is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070391005" comment="file is earlier than 0:4.10-3.0.2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070124006" comment="file is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070395" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0395: mod_perl security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0395-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0395.html" />
          <reference source="CVE" ref_id="CVE-2007-1349" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1349.html" />
    
    <description>Mod_perl incorporates a Perl interpreter into the Apache web server,
so that the Apache web server can directly execute Perl code.

An issue was found in the "namespace_from_uri" method of the
ModPerl::RegistryCooker class.  If a server implemented a mod_perl registry
module using this method, a remote attacker requesting a carefully crafted
URI can cause resource consumption, which could lead to a denial of service
(CVE-2007-1349).

Users of mod_perl should update to these erratum packages which contain a
backported fix to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-14" />
        <updated date="2007-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1349.html">CVE-2007-1349</cve>
                <bugzilla href="http://bugzilla.redhat.com/240423" id="240423">CVE-2007-1349 mod_perl PerlRun denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395004" comment="mod_perl-devel is earlier than 0:2.0.2-6.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395005" comment="mod_perl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395002" comment="mod_perl is earlier than 0:2.0.2-6.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395003" comment="mod_perl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395009" comment="mod_perl-devel is earlier than 0:1.99_09-12.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395010" comment="mod_perl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395007" comment="mod_perl is earlier than 0:1.99_09-12.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395008" comment="mod_perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395013" comment="mod_perl-devel is earlier than 0:1.99_16-4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395010" comment="mod_perl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070395012" comment="mod_perl is earlier than 0:1.99_16-4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070395008" comment="mod_perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070400" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0400: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0400-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0400.html" />
          <reference source="CVE" ref_id="CVE-2007-1362" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1362.html" />
          <reference source="CVE" ref_id="CVE-2007-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1562.html" />
          <reference source="CVE" ref_id="CVE-2007-2867" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2867.html" />
          <reference source="CVE" ref_id="CVE-2007-2868" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2868.html" />
          <reference source="CVE" ref_id="CVE-2007-2869" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2869.html" />
          <reference source="CVE" ref_id="CVE-2007-2870" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2870.html" />
          <reference source="CVE" ref_id="CVE-2007-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2871.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Firefox to crash or potentially execute arbitrary code as the user
running Firefox. (CVE-2007-2867, CVE-2007-2868)

A flaw was found in the way Firefox handled certain FTP PASV commands. A
malicious FTP server could use this flaw to perform a rudimentary
port-scan of machines behind a user's firewall. (CVE-2007-1562)

Several denial of service flaws were found in the way Firefox handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent Firefox from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way Firefox handled the addEventListener
JavaScript method. A malicious web site could use this method to access or
modify sensitive data from another web site. (CVE-2007-2870)

A flaw was found in the way Firefox displayed certain web content. A
malicious web page could generate content that would overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871)

Users of Firefox are advised to upgrade to these erratum packages, which
contain Firefox version 1.5.0.12 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1362.html">CVE-2007-1362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1562.html">CVE-2007-1562</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2867.html">CVE-2007-2867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2868.html">CVE-2007-2868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2869.html">CVE-2007-2869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2870.html">CVE-2007-2870</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2871.html">CVE-2007-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/241670" id="241670">CVE-2007-1362 Multiple Firefox flaws (CVE-2007-1562, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070400002" comment="devhelp is earlier than 0:0.12-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097003" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070400004" comment="devhelp-devel is earlier than 0:0.12-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097005" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070400008" comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097011" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070400006" comment="firefox is earlier than 0:1.5.0.12-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070400010" comment="yelp is earlier than 0:2.16.0-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097007" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070400013" comment="firefox is earlier than 0:1.5.0.12-0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070401" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0401: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0401-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0401.html" />
          <reference source="CVE" ref_id="CVE-2007-1362" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1362.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
          <reference source="CVE" ref_id="CVE-2007-2867" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2867.html" />
          <reference source="CVE" ref_id="CVE-2007-2868" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2868.html" />
          <reference source="CVE" ref_id="CVE-2007-2869" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2869.html" />
          <reference source="CVE" ref_id="CVE-2007-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2871.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Thunderbird to crash or potentially execute arbitrary code
as the user running Thunderbird. (CVE-2007-2867, CVE-2007-2868)

Several denial of service flaws were found in the way Thunderbird handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent Thunderbird from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way Thunderbird processed certain APOP
authentication requests. By sending certain responses when Thunderbird
attempted to authenticate against an APOP server, a remote attacker could
potentially acquire certain portions of a user's authentication
credentials. (CVE-2007-1558)

A flaw was found in the way Thunderbird displayed certain web content. A
malicious web page could generate content which could overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871)

Users of Thunderbird are advised to apply this update, which contains
Thunderbird version 1.5.0.12 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1362.html">CVE-2007-1362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2867.html">CVE-2007-2867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2868.html">CVE-2007-2868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2869.html">CVE-2007-2869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2871.html">CVE-2007-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/241671" id="241671">CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070401002" comment="thunderbird is earlier than 0:1.5.0.12-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070401005" comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070402" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0402: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0402-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0402.html" />
          <reference source="CVE" ref_id="CVE-2007-1362" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1362.html" />
          <reference source="CVE" ref_id="CVE-2007-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1562.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
          <reference source="CVE" ref_id="CVE-2007-2867" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2867.html" />
          <reference source="CVE" ref_id="CVE-2007-2868" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2868.html" />
          <reference source="CVE" ref_id="CVE-2007-2869" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2869.html" />
          <reference source="CVE" ref_id="CVE-2007-2870" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2870.html" />
          <reference source="CVE" ref_id="CVE-2007-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2871.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause SeaMonkey to crash or potentially execute arbitrary code as
the user running SeaMonkey. (CVE-2007-2867, CVE-2007-2868)

A flaw was found in the way SeaMonkey handled certain FTP PASV commands. A
malicious FTP server could use this flaw to perform a rudimentary port-scan
of machines behind a user's firewall. (CVE-2007-1562)

Several denial of service flaws were found in the way SeaMonkey handled
certain form and cookie data. A malicious web site that is able to set
arbitrary form and cookie data could prevent SeaMonkey from
functioning properly. (CVE-2007-1362, CVE-2007-2869)

A flaw was found in the way SeaMonkey processed certain APOP authentication
requests. By sending certain responses when SeaMonkey attempted to
authenticate against an APOP server, a remote attacker could potentially
acquire certain portions of a user's authentication credentials.
(CVE-2007-1558)

A flaw was found in the way SeaMonkey handled the addEventListener
JavaScript method. A malicious web site could use this method to access or
modify sensitive data from another web site. (CVE-2007-2870)

A flaw was found in the way SeaMonkey displayed certain web content. A
malicious web page could generate content that would overlay user
interface elements such as the hostname and security indicators, tricking 
users into thinking they are visiting a different site. (CVE-2007-2871) 

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain SeaMonkey version 1.0.9 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-30" />
        <updated date="2007-05-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1362.html">CVE-2007-1362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1562.html">CVE-2007-1562</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2867.html">CVE-2007-2867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2868.html">CVE-2007-2868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2869.html">CVE-2007-2869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2870.html">CVE-2007-2870</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2871.html">CVE-2007-2871</cve>
                <bugzilla href="http://bugzilla.redhat.com/241672" id="241672">CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402004" comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402020" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402012" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402018" comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402002" comment="seamonkey is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402014" comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402016" comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402006" comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402032" comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402025" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402024" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402027" comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402023" comment="seamonkey is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402029" comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402031" comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402030" comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402028" comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402026" comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402033" comment="devhelp is earlier than 0:0.10-0.8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077024" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070402035" comment="devhelp-devel is earlier than 0:0.10-0.8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077026" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070403" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0403: freetype security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0403-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0403.html" />
          <reference source="CVE" ref_id="CVE-2007-2754" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2754.html" />
    
    <description>FreeType is a free, high-quality,  portable font engine.

An integer overflow flaw was found in the way the FreeType font engine
processed TTF font files. If a user loaded a carefully crafted font file
with a program linked against FreeType, it could cause the application to
crash or execute arbitrary code. While it is uncommon for a user to
explicitly load a font file, there are several application file formats
which contain embedded fonts that are parsed by FreeType. (CVE-2007-2754)

Users of FreeType should upgrade to these updated packages, which contain
a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-11" />
        <updated date="2007-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2754.html">CVE-2007-2754</cve>
                <bugzilla href="http://bugzilla.redhat.com/240200" id="240200">CVE-2007-2754 freetype integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403002" comment="freetype is earlier than 0:2.2.1-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150003" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403004" comment="freetype-demos is earlier than 0:2.2.1-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150005" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403006" comment="freetype-devel is earlier than 0:2.2.1-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150007" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403013" comment="freetype-utils is earlier than 0:2.1.4-7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150014" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403009" comment="freetype is earlier than 0:2.1.4-7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403015" comment="freetype-demos is earlier than 0:2.1.4-7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150012" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403011" comment="freetype-devel is earlier than 0:2.1.4-7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150016" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403021" comment="freetype-utils is earlier than 0:2.1.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150014" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403018" comment="freetype is earlier than 0:2.1.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403020" comment="freetype-demos is earlier than 0:2.1.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150012" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070403019" comment="freetype-devel is earlier than 0:2.1.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070150016" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070406" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0406: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0406.html" />
          <reference source="CVE" ref_id="CVE-2007-0245" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0245.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the RTF import filer.  An attacker could
create a carefully crafted RTF file that could cause OpenOffice.org to
crash or possibly execute arbitrary code if the file was opened by a
victim. (CVE-2007-0245)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-13" />
        <updated date="2007-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0245.html">CVE-2007-0245</cve>
                <bugzilla href="http://bugzilla.redhat.com/242004" id="242004">CVE-2007-0245 openoffice.org rtf filter buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406002" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406020" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069131" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406052" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069061" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406078" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069093" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406142" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069081" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406140" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069041" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406010" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069143" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406072" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069017" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406030" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069037" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406118" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069059" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406036" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069113" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406004" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069077" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406100" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069083" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406018" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069137" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406024" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069011" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406014" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069097" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406086" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069031" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406144" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069049" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406088" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069091" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406062" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069119" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406124" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069141" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406060" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069023" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406012" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069053" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406102" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069021" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406116" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069013" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406108" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069135" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406104" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069149" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406046" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069127" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406068" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069115" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406094" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069139" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406098" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069109" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406022" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069099" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406120" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069057" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406126" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069107" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406054" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069125" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406026" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069025" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406136" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069015" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406034" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069045" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406080" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069007" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406084" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069101" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406076" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069117" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406038" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069063" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406096" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069087" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406128" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069029" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406008" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069095" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406148" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069105" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406134" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069071" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406050" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069043" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406058" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069085" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406042" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069111" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406056" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069035" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406066" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069103" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406112" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069065" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406070" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069073" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406146" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069075" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406090" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069145" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406064" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069123" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406082" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406028" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069005" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406032" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069067" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406006" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069047" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406130" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069079" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406106" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069051" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406132" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069009" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406074" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069055" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406122" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069039" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406044" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069089" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406114" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069147" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406048" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069027" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406138" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069133" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406040" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069129" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406016" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069069" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406110" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069121" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406092" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069019" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406153" comment="openoffice.org-i18n is earlier than 0:1.1.2-39.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406151" comment="openoffice.org is earlier than 0:1.1.2-39.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406155" comment="openoffice.org-libs is earlier than 0:1.1.2-39.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406162" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406158" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406160" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406159" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.1.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406253" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406254" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406245" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406246" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406233" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406234" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406207" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406208" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406197" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406198" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406195" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406196" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406187" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406188" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406171" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406172" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406255" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406256" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406247" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406248" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406223" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406224" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406211" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406212" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406165" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406166" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406277" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406278" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406215" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406216" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406189" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406190" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406265" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406266" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406191" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406192" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406177" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406178" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406193" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406194" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406163" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406164" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406279" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406280" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406273" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406274" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406269" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406270" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406263" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406264" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406259" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406260" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406257" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406258" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406249" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406250" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406235" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406236" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406227" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406228" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406209" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406210" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406185" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406186" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406173" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406174" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406251" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406252" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406213" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406214" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406201" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406202" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406199" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406200" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406179" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406180" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406261" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406262" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406243" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406244" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406241" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406242" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406237" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406238" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406221" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406222" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406203" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406204" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406183" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406184" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406169" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406170" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406275" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406276" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406229" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406230" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406219" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406220" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406175" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406176" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406271" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406272" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406267" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406268" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406239" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406240" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406231" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406232" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406225" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406226" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406217" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406218" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406205" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406206" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406167" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406168" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070406181" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.1.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406182" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070430" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0430: openldap security and bug-fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0430.html" />
          <reference source="CVE" ref_id="CVE-2006-4600" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4600.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access 
Protocol) applications, libraries and development tools.

A flaw was found in the way OpenLDAP handled selfwrite access. Users with
selfwrite access were able to modify the distinguished name of any user.
Users with selfwrite access should only be able to modify their own
distinguished name. (CVE-2006-4600)

A memory leak bug was found in OpenLDAP's ldap_start_tls_s() function. An
application using this function could result in an Out Of Memory (OOM)
condition, crashing the application.

All users are advised to upgrade to this updated openldap package, 
which contains a backported fix and is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2007-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4600.html">CVE-2006-4600</cve>
                <bugzilla href="http://bugzilla.redhat.com/174830" id="174830">ldap_start_tls_s() leaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234222" id="234222">CVE-2006-4600 openldap improper selfwrite access</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070430006" comment="openldap-devel is earlier than 0:2.0.27-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310009" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070430008" comment="openldap-clients is earlier than 0:2.0.27-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310007" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070430002" comment="openldap is earlier than 0:2.0.27-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070430004" comment="openldap-servers is earlier than 0:2.0.27-23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310005" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070431" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0431: shadow-utils security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0431.html" />
          <reference source="CVE" ref_id="CVE-2006-1174" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1174.html" />
    
    <description>The shadow-utils package includes the necessary programs for converting
UNIX password files to the shadow password format, as well as programs 
for managing user and group accounts. 

A flaw was found in the useradd tool in shadow-utils. A new user's
mailbox, when created, could have random permissions for a short period.
This could allow a local attacker to read or modify the mailbox.
(CVE-2006-1174)

This update also fixes the following bugs:

* shadow-utils debuginfo package was empty.

* chage.1 and chage -l gave incorrect information about sp_inact.

All users of shadow-utils are advised to upgrade to this updated 
package, which contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1174.html">CVE-2006-1174</cve>
                <bugzilla href="http://bugzilla.redhat.com/176949" id="176949">shadow-utils-debuginfo is empty</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/216635" id="216635">chage does not show the Account Expires if its shadow field is 0.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229194" id="229194">CVE-2006-1174 shadow-utils mailbox creation race condition</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070431002" comment="shadow-utils is earlier than 2:4.0.3-29.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070276003" comment="shadow-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070436" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0436: Updated kernel packages for Red Hat Enterprise Linux 3 Update 9 (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0436.html" />
          <reference source="CVE" ref_id="CVE-2006-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5823.html" />
          <reference source="CVE" ref_id="CVE-2006-6054" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6054.html" />
          <reference source="CVE" ref_id="CVE-2007-1592" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1592.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

This is the ninth regular kernel update to Red Hat Enterprise Linux 3.

There were no new features introduced by this update.  The only changes
that have been included address critical customer needs or security
issues (elaborated below).

Key areas affected by fixes in this update include the networking
subsystem, dcache handling, the ext2 and ext3 file systems, the USB
subsystem, ACPI handling, and the audit subsystem.  There were also
several isolated fixes in the tg3, e1000, megaraid_sas, and aacraid
device drivers.

The following security bugs were fixed in this update:

  * a flaw in the cramfs file system that allowed invalid compressed
     data to cause memory corruption (CVE-2006-5823, low)

  * a flaw in the ext2 file system that allowed an invalid inode size
     to cause a denial of service (system hang)  (CVE-2006-6054, low)

  * a flaw in IPV6 flow label handling that allowed a local user to
     cause a denial of service (crash)  (CVE-2007-1592, important)

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5823.html">CVE-2006-5823</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6054.html">CVE-2006-6054</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1592.html">CVE-2007-1592</cve>
                <bugzilla href="http://bugzilla.redhat.com/128616" id="128616">acl permissions over nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/137374" id="137374">Need fix for: [NETFILTER]: Fix checksum bug for multicast/broadcast packets on postrouting hook.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/144794" id="144794">tg3 driver on BCM5703X won't load. Says tg3: Could not obtain valid ethernet address, aborting.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/164855" id="164855">u5 patch that turned on Dprintk's in arch/x86_64/kernel/smpboot.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171007" id="171007">powermate module does not recognize Griffin Powermate device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/173350" id="173350">jbd I/O errors after ext3 orphan processing on readonly device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/177300" id="177300">hugetlb_get_unmapped_area may overflow in X86_64 compat mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189052" id="189052">Kernel panic on shutdown or poweroff on SMP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/192796" id="192796">cut/paste bug in kscand</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/199542" id="199542">Data corruption after IO error on swap (RHEL3)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/209154" id="209154">High speed USB HID devices not working in RHEL3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/213635" id="213635">32-bit fstat on 64-bit kernel returns EOVERFLOW when st_ino gets too large</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/216960" id="216960">CVE-2006-5823 zlib_inflate memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217022" id="217022">CVE-2006-6054 ext2_check_page denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/217930" id="217930">[RHEL3] Netdump for 8139cp driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/224600" id="224600">running 32-bit executables on x86_64/ia64/s390x causes negative "vm_committed_space" value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/226895" id="226895">Kernel oops when loading ipmi_si module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231912" id="231912">Laus doesn't audit detach event</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232221" id="232221">Laus dev.audit.attach-all doesn't attach to init</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232336" id="232336">Enable use of PAL_HALT_LIGHT for idle loop as non-default option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233262" id="233262">ipv6 OOPS triggerable by any user</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436004" comment="kernel-source is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436002" comment="kernel is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436008" comment="kernel-doc is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436016" comment="kernel-hugemem is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436014" comment="kernel-BOOT is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436013" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436010" comment="kernel-unsupported is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070436006" comment="kernel-smp is earlier than 0:2.4.21-50.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070465" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0465: pam security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0465.html" />
          <reference source="CVE" ref_id="CVE-2004-0813" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-0813.html" />
          <reference source="CVE" ref_id="CVE-2007-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1716.html" />
    
    <description>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

A flaw was found in the way the Linux kernel handled certain SG_IO
commands. Console users with access to certain device files had the ability
to damage recordable CD drives. The way pam_console handled permissions of
these files has been modified to disallow access. This change also required
modifications to the cdrecord application. (CVE-2004-0813)

A flaw was found in the way pam_console set console device permissions. It
was possible for various console devices to retain ownership of the console
user after logging out, possibly leaking information to an unauthorized
user. (CVE-2007-1716)

The pam_unix module provides authentication against standard /etc/passwd
and /etc/shadow files. The pam_stack module provides support for stacking
PAM configuration files. Both of these modules contained small memory leaks
which caused problems in applications calling PAM authentication repeatedly
in the same process.

All users of PAM should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-0813.html">CVE-2004-0813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1716.html">CVE-2007-1716</cve>
                <bugzilla href="http://bugzilla.redhat.com/133098" id="133098">CVE-2004-0813 SG_IO unsafe user command execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/204055" id="204055">Possibly memory leak in pam modules.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230625" id="230625">4byte leak in pam_unix.so</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232096" id="232096">CVE-2004-0813 SG_IO unsafe user command execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234142" id="234142">CVE-2007-1716 Ownership of devices not returned to root after logout from console</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465004" comment="pam-devel is earlier than 0:0.75-72" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465005" comment="pam-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465002" comment="pam is earlier than 0:0.75-72" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465003" comment="pam is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465014" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465015" comment="cdrecord is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465012" comment="cdda2wav is earlier than 8:2.01.0.a32-0.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465013" comment="cdda2wav is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465006" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465007" comment="cdrtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465010" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465011" comment="cdrecord-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070465008" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465009" comment="mkisofs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070469" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0469: gdb security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0469-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0469.html" />
          <reference source="CVE" ref_id="CVE-2006-4146" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4146.html" />
    
    <description>GDB, the GNU debugger, allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and then printing
their data.

Various buffer overflows and underflows were found in the DWARF expression
computation stack in GDB.  If an attacker could trick a user into loading
an executable containing malicious debugging information into GDB, they may
be able to execute arbitrary code with the privileges of the user.
(CVE-2006-4146)

This updated package also addresses the following issues:

* Support on 64-bit hosts shared libraries debuginfo larger than 2GB.

* Fix a race occasionally leaving the detached processes stopped.

* Fix segmentation fault on the source display by ^X 1.

* Fix a crash on an opaque type dereference.

All users of gdb should upgrade to this updated package, which contains
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2007-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4146.html">CVE-2006-4146</cve>
                <bugzilla href="http://bugzilla.redhat.com/135488" id="135488">gdb internal error with incomplete type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189607" id="189607">pstack can cause process to suspend</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/203875" id="203875">CVE-2006-4146 GDB buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070469002" comment="gdb is earlier than 0:6.3.0.0-1.138.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070229003" comment="gdb is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070473" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0473: gcc security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0473-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0473.html" />
          <reference source="CVE" ref_id="CVE-2006-3619" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3619.html" />
    
    <description>The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95
GNU compilers and related support libraries.

Jürgen Weigert discovered a directory traversal flaw in fastjar. An
attacker could create a malicious JAR file which, if unpacked using
fastjar, could write to any files the victim had write access to.
(CVE-2006-3619)

These updated packages also fix a reload internal compiler error with
-fnon-call-exceptions option.

All users of gcc should upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-08" />
        <updated date="2007-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3619.html">CVE-2006-3619</cve>
                <bugzilla href="http://bugzilla.redhat.com/225552" id="225552">CVE-2006-3619 Directory traversal issue in jar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/226706" id="226706">Attached code crashes the compiler, error at: reload1.c:9508</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473012" comment="gcc-g77 is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220031" comment="gcc-g77 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473024" comment="libgcj-devel is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220025" comment="libgcj-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473006" comment="libgcc is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220017" comment="libgcc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473034" comment="cpp is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220023" comment="cpp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473028" comment="gcc-gnat is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220027" comment="gcc-gnat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473008" comment="libstdc++ is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220013" comment="libstdc++ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473030" comment="libf2c is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220035" comment="libf2c is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473020" comment="gcc-c++-ppc32 is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220029" comment="gcc-c++-ppc32 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473014" comment="gcc-objc is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220007" comment="gcc-objc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473010" comment="gcc-c++ is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220015" comment="gcc-c++ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473002" comment="gcc is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220003" comment="gcc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473026" comment="gcc-java is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220005" comment="gcc-java is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473022" comment="libstdc++-devel is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220009" comment="libstdc++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473016" comment="libgnat is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220021" comment="libgnat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473004" comment="libgcj is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220033" comment="libgcj is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473032" comment="gcc-ppc32 is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220011" comment="gcc-ppc32 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070473018" comment="libobjc is earlier than 0:3.2.3-59" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070220019" comment="libobjc is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070488" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0488: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0488-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0488.html" />
          <reference source="CVE" ref_id="CVE-2006-5158" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5158.html" />
          <reference source="CVE" ref_id="CVE-2006-7203" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7203.html" />
          <reference source="CVE" ref_id="CVE-2007-0773" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0773.html" />
          <reference source="CVE" ref_id="CVE-2007-0958" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0958.html" />
          <reference source="CVE" ref_id="CVE-2007-1353" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1353.html" />
          <reference source="CVE" ref_id="CVE-2007-2172" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2172.html" />
          <reference source="CVE" ref_id="CVE-2007-2525" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2525.html" />
          <reference source="CVE" ref_id="CVE-2007-2876" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2876.html" />
          <reference source="CVE" ref_id="CVE-2007-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3104.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the connection tracking support for SCTP that allowed a remote
user to cause a denial of service by dereferencing a NULL pointer.
(CVE-2007-2876, Important)

* a flaw in the mount handling routine for 64-bit systems that allowed a
local user to cause denial of service (crash). (CVE-2006-7203, Important)

* a flaw in the IPv4 forwarding base that allowed a local user to cause an
out-of-bounds access. (CVE-2007-2172, Important)

* a flaw in the PPP over Ethernet implementation that allowed a local user
to cause a denial of service (memory consumption) by creating a socket
using connect and then releasing it before the PPPIOCGCHAN ioctl has been
called. (CVE-2007-2525, Important)

* a flaw in the fput ioctl handling of 32-bit applications running on
64-bit platforms that allowed a local user to cause a denial of service
(panic). (CVE-2007-0773, Important)

* a flaw in the NFS locking daemon that allowed a local user to cause
denial of service (deadlock). (CVE-2006-5158, Moderate)

* a flaw in the sysfs_readdir function that allowed a local user to cause a
denial of service by dereferencing a NULL pointer. (CVE-2007-3104, Moderate)

* a flaw in the core-dump handling that allowed a local user to create core
dumps from unreadable binaries via PT_INTERP. (CVE-2007-0958, Low) 

* a flaw in the Bluetooth subsystem that allowed a local user to trigger an
information leak. (CVE-2007-1353, Low)

In addition, the following bugs were addressed:

* the NFS could recurse on the same spinlock. Also, NFS, under certain
conditions, did not completely clean up Posix locks on a file close,
leading to mount failures.

* the 32bit compatibility didn't return to userspace correct values for the
rt_sigtimedwait system call.

* the count for unused inodes could be incorrect at times, resulting in
dirty data not being written to disk in a timely manner.

* the cciss driver had an incorrect disk size calculation (off-by-one
error) which prevented disk dumps.

Red Hat would like to thank Ilja van Sprundel and the OpenVZ Linux kernel
team for reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-25" />
        <updated date="2007-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5158.html">CVE-2006-5158</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7203.html">CVE-2006-7203</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0773.html">CVE-2007-0773</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0958.html">CVE-2007-0958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1353.html">CVE-2007-1353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2172.html">CVE-2007-2172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2525.html">CVE-2007-2525</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2876.html">CVE-2007-2876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3104.html">CVE-2007-3104</cve>
                <bugzilla href="http://bugzilla.redhat.com/240855" id="240855">kernel spinlock panic in inode.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241784" id="241784">dirty data is not flushed on a timely manner</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242558" id="242558">CVE-2007-3104 Null pointer to an inode in a dentry can cause an oops in sysfs_readdir</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243251" id="243251">CVE-2006-5158 NFS lockd deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243252" id="243252">CVE-2007-0773 lost fput in a 32-bit ioctl on 64-bit x86 systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243256" id="243256">CVE-2007-0958 core-dumping unreadable binaries via PT_INTERP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243259" id="243259">CVE-2007-1353 Bluetooth setsockopt() information leaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243261" id="243261">CVE-2007-2172 fib_semantics.c out of bounds access vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243262" id="243262">CVE-2007-2525 PPPoE socket PPPIOCGCHAN denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243263" id="243263">CVE-2006-7203 oops in compat_sys_mount() when data pointer is NULL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243746" id="243746">CVE-2007-2876 {ip, nf}_conntrack_sctp: remotely triggerable NULL ptr dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243902" id="243902">diskdump to cciss  fails due to off-by-one size calculation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488002" comment="kernel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488022" comment="kernel-doc is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488004" comment="kernel-devel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488006" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488018" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488014" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488010" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488011" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488008" comment="kernel-xenU is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488009" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070488012" comment="kernel-smp is earlier than 0:2.6.9-55.0.2.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070492" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0492: spamassassin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0492-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0492.html" />
          <reference source="CVE" ref_id="CVE-2007-2873" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2873.html" />
    
    <description>SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.

Martin Krafft discovered a symlink issue in SpamAssassin that affects
certain non-default configurations. A local user could use this flaw to
create or overwrite files writable by the spamd process (CVE-2007-2873).

Users of SpamAssassin should upgrade to these updated packages which
contain a backported patch to correct this issue.

Note: This issue did not affect the version of SpamAssassin shipped with
Red Hat Enterprise Linux 3.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-13" />
        <updated date="2007-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2873.html">CVE-2007-2873</cve>
                <bugzilla href="http://bugzilla.redhat.com/243455" id="243455">CVE-2007-2873 spamassassin symlink attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070492002" comment="spamassassin is earlier than 0:3.1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070075003" comment="spamassassin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070492005" comment="spamassassin is earlier than 0:3.1.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070074003" comment="spamassassin is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070494" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0494: kdebase security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0494-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0494.html" />
          <reference source="CVE" ref_id="CVE-2007-2022" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2022.html" />
    
    <description>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager. 

A problem with the interaction between the Flash Player and the Konqueror
web browser was found. The problem could lead to key presses leaking to the
Flash Player applet instead of the browser (CVE-2007-2022).

Users of Konqueror who have installed the Adobe Flash Player plugin should
upgrade to these updated packages, which contain a patch provided by Dirk
Müller that protects against this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-13" />
        <updated date="2007-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2022.html">CVE-2007-2022</cve>
                <bugzilla href="http://bugzilla.redhat.com/243617" id="243617">CVE-2007-2022 kdebase3 flash-player interaction problem</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494002" comment="kdebase is earlier than 6:3.5.4-13.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494003" comment="kdebase is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494004" comment="kdebase-devel is earlier than 6:3.5.4-13.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494005" comment="kdebase-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494007" comment="kdebase is earlier than 6:3.1.3-5.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494008" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494009" comment="kdebase-devel is earlier than 6:3.1.3-5.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494010" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494012" comment="kdebase is earlier than 6:3.3.1-5.19.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494008" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070494013" comment="kdebase-devel is earlier than 6:3.3.1-5.19.rhel4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494010" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070497" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0497: iscsi-initiator-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0497-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0497.html" />
          <reference source="CVE" ref_id="CVE-2007-3099" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3099.html" />
          <reference source="CVE" ref_id="CVE-2007-3100" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3100.html" />
    
    <description>The iscsi package provides the server daemon for the iSCSI protocol, as
well as the utility programs used to manage it. iSCSI is a protocol for
distributed disk access using SCSI commands sent over Internet Protocol
networks.

Olaf Kirch discovered two flaws in open-iscsi.  A local attacker could use
these flaws to cause the server daemon to stop responding, leading to a
denial of service.  (CVE-2007-3099, CVE-2007-3100).

All users of open-iscsi should upgrade to this updated package which
resolves these issues.

Note: This issue did not affect Red Hat Enterprise Linux 2.1, 3, or 4.
open-iscsi is available in Red Hat Enterprise Linux 5 as a Technology
Preview.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-14" />
        <updated date="2007-06-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3099.html">CVE-2007-3099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3100.html">CVE-2007-3100</cve>
                <bugzilla href="http://bugzilla.redhat.com/243719" id="243719">CVE-2007-3099 dos flaws in open-iscsi (CVE-2007-3100)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070497002" comment="iscsi-initiator-utils is earlier than 0:6.2.0.742-0.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070497003" comment="iscsi-initiator-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070501" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0501: libexif integer overflow (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0501-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0501.html" />
          <reference source="CVE" ref_id="CVE-2006-4168" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4168.html" />
    
    <description>The libexif package contains the EXIF library. Applications use this
library to parse EXIF image files.

An integer overflow flaw was found in the way libexif parses EXIF image
tags. If a victim opens a carefully crafted EXIF image file it could cause
the application linked against libexif to execute arbitrary code or crash.
(CVE-2007-4168)

Users of libexif should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4168.html">CVE-2006-4168</cve>
                <bugzilla href="http://bugzilla.redhat.com/243888" id="243888">CVE-2006-4168 libexif integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070501004" comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501005" comment="libexif-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070501002" comment="libexif is earlier than 0:0.6.13-4.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501003" comment="libexif is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070501009" comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501010" comment="libexif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070501007" comment="libexif is earlier than 0:0.5.12-5.1.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501008" comment="libexif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070509" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0509: evolution security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0509-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0509.html" />
          <reference source="CVE" ref_id="CVE-2007-3257" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3257.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A flaw was found in the way Evolution processes certain IMAP server
messages. If a user can be tricked into connecting to a malicious IMAP
server it may be possible to execute arbitrary code as the user running
evolution. (CVE-2007-3257)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-25" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3257.html">CVE-2007-3257</cve>
                <bugzilla href="http://bugzilla.redhat.com/244277" id="244277">CVE-2007-3257 evolution malicious server arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070509002" comment="evolution is earlier than 0:1.4.5-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070509004" comment="evolution-devel is earlier than 0:1.4.5-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070509007" comment="evolution is earlier than 0:2.0.2-35.0.4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070509008" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070353005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070510" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0510: evolution-data-server security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0510-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0510.html" />
          <reference source="CVE" ref_id="CVE-2007-3257" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3257.html" />
    
    <description>The evolution-data-server package provides a unified backend for programs
that work with contacts, tasks, and calendar information.

A flaw was found in the way evolution-data-server processes certain IMAP
server messages. If a user can be tricked into connecting to a malicious
IMAP server it may be possible to execute arbitrary code as the user
running the evolution-data-server process. (CVE-2007-3257) 

All users of evolution-data-server should upgrade to these updated
packages, which contain a backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-25" />
        <updated date="2007-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3257.html">CVE-2007-3257</cve>
                <bugzilla href="http://bugzilla.redhat.com/244277" id="244277">CVE-2007-3257 evolution malicious server arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070510002" comment="evolution-data-server is earlier than 0:1.8.0-15.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070344003" comment="evolution-data-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070510004" comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070344005" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070513" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0513: gimp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0513-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0513.html" />
          <reference source="CVE" ref_id="CVE-2006-4519" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4519.html" />
          <reference source="CVE" ref_id="CVE-2007-2949" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2949.html" />
          <reference source="CVE" ref_id="CVE-2007-3741" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3741.html" />
    
    <description>The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

Multiple integer overflow and input validation flaws were found in The
GIMP's image loaders.  An attacker could create a carefully crafted image
file that could cause The GIMP to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2006-4519, CVE-2007-2949,
CVE-2007-3741)

Users of The GIMP should update to these erratum packages, which contain a
backported fix to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-26" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4519.html">CVE-2006-4519</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2949.html">CVE-2007-2949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3741.html">CVE-2007-3741</cve>
                <bugzilla href="http://bugzilla.redhat.com/244400" id="244400">CVE-2007-2949 Gimp PSD integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247565" id="247565">CVE-2006-4519 GIMP multiple image loader integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248053" id="248053">CVE-2007-3741 Gimp image loader multiple input validation flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513004" comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343007" comment="gimp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513006" comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343005" comment="gimp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513002" comment="gimp is earlier than 2:2.2.13-2.0.7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343003" comment="gimp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513011" comment="gimp-perl is earlier than 1:1.2.3-20.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343012" comment="gimp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513013" comment="gimp-devel is earlier than 1:1.2.3-20.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343014" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513009" comment="gimp is earlier than 1:1.2.3-20.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343010" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513017" comment="gimp-devel is earlier than 1:2.0.5-7.0.7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343014" comment="gimp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070513016" comment="gimp is earlier than 1:2.0.5-7.0.7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070343010" comment="gimp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070519" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0519: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0519-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0519.html" />
          <reference source="CVE" ref_id="CVE-2007-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3103.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A temporary file flaw was found in the way the X.Org X11 xfs font server
startup script executes. A local user could modify the permissions of the
file of their choosing, possibly elevating their local privileges
(CVE-2007-3103).

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-12" />
        <updated date="2007-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3103.html">CVE-2007-3103</cve>
                <bugzilla href="http://bugzilla.redhat.com/242907" id="242907">CVE-2007-3103 init.d xfs script chown race condition vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519016" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003023" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519030" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003027" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519032" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003015" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519022" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003005" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519018" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003009" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519012" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003037" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519010" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003007" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519014" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519024" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003029" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519004" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003021" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519036" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519028" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003035" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519026" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003031" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519020" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003033" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519034" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003019" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519008" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003011" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070519006" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003017" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070520" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0520: xorg-x11-xfs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0520-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0520.html" />
          <reference source="CVE" ref_id="CVE-2007-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3103.html" />
    
    <description>The X.Org X11 xfs font server provides a standard mechanism for an X server
to communicate with a font renderer.

A temporary file flaw was found in the way the X.Org X11 xfs font server
startup script executes. A local user could modify the permissions of a
file of their choosing, possibly elevating their local privileges.
(CVE-2007-3103)

Users of the X.org X11 xfs font server should upgrade to these updated
packages, which contain a backported patch and are not vulnerable to this
issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-12" />
        <updated date="2007-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3103.html">CVE-2007-3103</cve>
                <bugzilla href="http://bugzilla.redhat.com/242903" id="242903">CVE-2007-3103 init.d xfs script chown race condition vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070520002" comment="xorg-x11-xfs is earlier than 1:1.0.2-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070520003" comment="xorg-x11-xfs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070520004" comment="xorg-x11-xfs-utils is earlier than 1:1.0.2-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070520005" comment="xorg-x11-xfs-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070533" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0533: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0533-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0533.html" />
          <reference source="CVE" ref_id="CVE-2006-5752" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5752.html" />
          <reference source="CVE" ref_id="CVE-2007-1863" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1863.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the Apache HTTP Server mod_status module. On sites
where the server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack. On Red Hat
Enterprise Linux the server-status page is not enabled by default and it is
best practice to not make this publicly available. (CVE-2006-5752)

A flaw was found in the Apache HTTP Server mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-1863)

In addition, two bugs were fixed:

* when the ProxyErrorOverride directive was enabled, responses with 3xx
status-codes would be overriden at the proxy. This has been changed so that
only 4xx and 5xx responses are overriden.

* the "ProxyTimeout" directive was not inherited across virtual host
definitions.

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart Apache
after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-27" />
        <updated date="2007-06-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5752.html">CVE-2006-5752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1863.html">CVE-2007-1863</cve>
                <bugzilla href="http://bugzilla.redhat.com/244638" id="244638">Reverse Proxy Unexpected Timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244639" id="244639">Mod_proxy_http ProxyErrorOverride eating cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244658" id="244658">CVE-2007-1863 httpd mod_cache segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245112" id="245112">CVE-2006-5752 httpd mod_status XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070533006" comment="httpd-devel is earlier than 0:2.0.46-67.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070533004" comment="mod_ssl is earlier than 0:2.0.46-67.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070533002" comment="httpd is earlier than 0:2.0.46-67.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070534" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0534: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0534-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0534.html" />
          <reference source="CVE" ref_id="CVE-2006-5752" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5752.html" />
          <reference source="CVE" ref_id="CVE-2007-1863" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1863.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the Apache HTTP Server mod_status module. On sites
where the server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack. On Red Hat
Enterprise Linux the server-status page is not enabled by default and it is
best practice to not make this publicly available. (CVE-2006-5752)

A bug was found in the Apache HTTP Server mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-1863)

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart Apache
after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-06-26" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5752.html">CVE-2006-5752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1863.html">CVE-2007-1863</cve>
                <bugzilla href="http://bugzilla.redhat.com/244658" id="244658">CVE-2007-1863 httpd mod_cache segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245112" id="245112">CVE-2006-5752 httpd mod_status XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070534004" comment="httpd-manual is earlier than 0:2.0.52-32.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534005" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070534010" comment="httpd-suexec is earlier than 0:2.0.52-32.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070534008" comment="httpd-devel is earlier than 0:2.0.52-32.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070534006" comment="mod_ssl is earlier than 0:2.0.52-32.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070534002" comment="httpd is earlier than 0:2.0.52-32.2.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070539" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0539: aide security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0539-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0539.html" />
          <reference source="CVE" ref_id="CVE-2007-3849" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3849.html" />
    
    <description>Advanced Intrusion Detection Environment (AIDE) is a file integrity checker
and intrusion detection program.

A flaw was discovered in the way file checksums were stored in the AIDE
database. A packaging flaw in the Red Hat AIDE rpm resulted in the file
database not containing any file checksum information. This could prevent
AIDE from detecting certain file modifications. (CVE-2007-3849)

This update also fixes the following bugs:

* certain configurations could result in a segmentation fault upon
initialization.

* AIDE was unable to open its log file in the LSPP evaluated configuration.

* if AIDE found SELinux context differences, the changed files report it
generated only included the first 32 characters of the context.

All users of AIDE are advised to upgrade to this updated package containing
AIDE version 0.13.1 which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3849.html">CVE-2007-3849</cve>
                <bugzilla href="http://bugzilla.redhat.com/225089" id="225089">aide Segmentation fault on initialization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236855" id="236855">LSPP: aide can't write its log file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236923" id="236923">CVE-2007-3849 Rebase aide to 0.13.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240144" id="240144">[LSPP] aide report output limits context to 32char -- not evaluation blocking</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070539002" comment="aide is earlier than 0:0.13.1-2.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070539003" comment="aide is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070540" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0540: openssh security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0540-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0540.html" />
          <reference source="CVE" ref_id="CVE-2006-5052" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5052.html" />
          <reference source="CVE" ref_id="CVE-2007-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3102.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the way the ssh server wrote account names to the audit
subsystem. An attacker could inject strings containing parts of audit
messages, which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

A flaw was found in the way the OpenSSH server processes GSSAPI
authentication requests. When GSSAPI authentication was enabled in the
OpenSSH server, a remote attacker was potentially able to determine if a
username is valid. (CVE-2006-5052)

The following bugs in SELinux MLS (Multi-Level Security) support has also
been fixed in this update:

* It was sometimes not possible to select a SELinux role and level when
logging in using ssh.

* If the user obtained a non-default SELinux role or level, the role change
was not recorded in the audit subsystem.

* In some cases, on labeled networks, sshd allowed logins from level ranges
it should not allow.

The updated packages also contain experimental support for using private
keys stored in PKCS#11 tokens for client authentication. The support is
provided through the NSS (Network Security Services) library.

All users of openssh should upgrade to these updated packages, which
contain patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5052.html">CVE-2006-5052</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3102.html">CVE-2007-3102</cve>
                <bugzilla href="http://bugzilla.redhat.com/227733" id="227733">[LSPP] unable to ssh into a system as root/auditadm_r</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229278" id="229278">LSPP: ssh-mls allows a level through that it should not</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231695" id="231695">LSPP: user unable to ssh to system with user/role/level context</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234638" id="234638">CVE-2006-5052 GSSAPI information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234951" id="234951">[LSPP] openssh server fails to parse level correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248059" id="248059">CVE-2007-3102 audit logging of failed logins</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070540002" comment="openssh is earlier than 0:4.3p2-24.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070540003" comment="openssh is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070540006" comment="openssh-clients is earlier than 0:4.3p2-24.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070540007" comment="openssh-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070540004" comment="openssh-server is earlier than 0:4.3p2-24.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070540005" comment="openssh-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070540008" comment="openssh-askpass is earlier than 0:4.3p2-24.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070540009" comment="openssh-askpass is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070542" version="506" class="patch">
      <metadata>
        <title>RHSA-2007:0542: mcstrans security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0542-05" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0542.html" />
          <reference source="CVE" ref_id="CVE-2007-4570" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4570.html" />
    
    <description>mcstrans is the translation daemon used on SELinux machines to translate
program context into human readable form.

An algorithmic complexity weakness was found in the way the mcstrans daemon
handled ranges of compartments in sensitivity labels. A local user could
trigger this flaw causing mctransd to temporarily stop responding to other
requests; a partial denial of service.  (CVE-2007-4570)

This update also fixes a problem where the mcstrans daemon was preventing
SSH connections into an SELinux box, that was running a Multi-Level
Security (MLS) Policy with multiple categories.

Users of mcstrans are advised to upgrade to this updated package, which
resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4570.html">CVE-2007-4570</cve>
                <bugzilla href="http://bugzilla.redhat.com/228398" id="228398">LSPP: Not able to ssh into the machine with multiple categories</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/288201" id="288201">CVE-2007-4570 mctransd DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070542002" comment="mcstrans is earlier than 0:0.2.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070542003" comment="mcstrans is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070555" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0555: pam security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0555-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0555.html" />
          <reference source="CVE" ref_id="CVE-2007-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1716.html" />
          <reference source="CVE" ref_id="CVE-2007-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3102.html" />
    
    <description>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

A flaw was found in the way pam_console set console device permissions. It
was possible for various console devices to retain ownership of the console
user after logging out, possibly leaking information to another local user.
(CVE-2007-1716)

A flaw was found in the way the PAM library wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

As well, these updated packages fix the following bugs:

* truncated MD5-hashed passwords in "/etc/shadow" were treated as valid, 
resulting in insecure and invalid passwords.

* the pam_namespace module did not convert context names to raw format and
did not unmount polyinstantiated directories in some cases. It also crashed
when an unknown user name was used in "/etc/security/namespace.conf", the
pam_namespace configuration file.

* the pam_selinux module was not relabeling the controlling tty correctly,
and in some cases it did not send complete information about user role and
level change to the audit subsystem.

These updated packages add the following enhancements:

* pam_limits module now supports parsing additional config files placed
into the /etc/security/limits.d/ directory. These files are read after the
main configuration file.

* the modules pam_limits, pam_access, and pam_time now send a message to
the audit subsystem when a user is denied access based on the number of
login sessions, origin of user, and time of login.

* pam_unix module security properties were improved. Functionality in the
setuid helper binary, unix_chkpwd, which was not required for user
authentication, was moved to a new non-setuid helper binary, unix_update.

All users of PAM should upgrade to these updated packages, which resolve
these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1716.html">CVE-2007-1716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3102.html">CVE-2007-3102</cve>
                <bugzilla href="http://bugzilla.redhat.com/227345" id="227345">pam_namespace should convert the context names before it uses them as filenames</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230120" id="230120">LSPP: Not able to log into the machine with large number of categories</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232993" id="232993">FIPS 200: audit rejection based on number of sessions, origin and time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233581" id="233581">CVE-2007-1716 Ownership of devices not returned to root after logout from console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234513" id="234513">[LSPP] pam_namespace crashes with non-existent users in namespace.conf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234781" id="234781">[LSPP] incorrect information in pam_selinux audit record</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236316" id="236316">LSPP: Unable to change expired password on ssh login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237163" id="237163">namespace.conf: $HOME used in polyinstantiated directory name not being expanded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237249" id="237249">LSPP: polyinstantiation behavior correct and documented</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243204" id="243204">CVE-2007-3102 audit logging of failed logins</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070555004" comment="pam-devel is earlier than 0:0.99.6.2-3.26.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070555005" comment="pam-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070555002" comment="pam is earlier than 0:0.99.6.2-3.26.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070555003" comment="pam is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070556" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0556: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0556-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0556.html" />
          <reference source="CVE" ref_id="CVE-2006-5752" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5752.html" />
          <reference source="CVE" ref_id="CVE-2007-1863" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1863.html" />
          <reference source="CVE" ref_id="CVE-2007-3304" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3304.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

The Apache HTTP Server did not verify that a process was an Apache child
process before sending it signals. A local attacker with the ability to run
scripts on the Apache HTTP Server could manipulate the scoreboard and cause
arbitrary processes to be terminated which could lead to a denial of
service (CVE-2007-3304).  This issue is not exploitable on Red Hat
Enterprise Linux 5 if using the default SELinux targeted policy.

A flaw was found in the Apache HTTP Server mod_status module. On sites
where the server-status page is publicly accessible and ExtendedStatus is
enabled this could lead to a cross-site scripting attack. On Red Hat
Enterprise Linux the server-status page is not enabled by default and it is
best practice to not make this publicly available. (CVE-2006-5752)

A bug was found in the Apache HTTP Server mod_cache module. On sites where
caching is enabled, a remote attacker could send a carefully crafted
request that would cause the Apache child process handling that request to
crash. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-1863)

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart Apache
after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-26" />
        <updated date="2007-06-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5752.html">CVE-2006-5752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1863.html">CVE-2007-1863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3304.html">CVE-2007-3304</cve>
                <bugzilla href="http://bugzilla.redhat.com/244658" id="244658">CVE-2007-1863 httpd mod_cache segfault</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245111" id="245111">CVE-2007-3304 httpd scoreboard lack of PID protection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245112" id="245112">CVE-2006-5752 httpd mod_status XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070556008" comment="httpd-manual is earlier than 0:2.2.3-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556009" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070556004" comment="httpd-devel is earlier than 0:2.2.3-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556005" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070556006" comment="mod_ssl is earlier than 0:2.2.3-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556007" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070556002" comment="httpd is earlier than 0:2.2.3-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070559" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0559: cman security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0559-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0559.html" />
          <reference source="CVE" ref_id="CVE-2007-3374" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3374.html" />
    
    <description>cman is the Red Hat Cluster Manager.

A flaw was found in the cman daemon.  A local attacker could connect to the
cman daemon and trigger a static buffer overflow leading to a denial of
service or, potentially, an escalation of privileges.  (CVE-2007-3374)

Users of Cluster Manager should upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-28" />
        <updated date="2007-12-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3374.html">CVE-2007-3374</cve>
                <bugzilla href="http://bugzilla.redhat.com/244891" id="244891">CVE-2007-3374 possible buffer overflow could cause local DoS by crashing cman</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070559002" comment="cman is earlier than 0:2.0.64-1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070559003" comment="cman is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070559004" comment="cman-devel is earlier than 0:2.0.64-1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070559005" comment="cman-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070562" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0562: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0562-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0562.html" />
          <reference source="CVE" ref_id="CVE-2007-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2442.html" />
          <reference source="CVE" ref_id="CVE-2007-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2443.html" />
          <reference source="CVE" ref_id="CVE-2007-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2798.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

David Coffey discovered an uninitialized pointer free flaw in the RPC
library used by kadmind.  On Red Hat Enterprise Linux 4 and 5, glibc
detects attempts to free invalid pointers.  A remote unauthenticated
attacker who can access kadmind could trigger this flaw and cause kadmind
to crash. (CVE-2007-2442)

David Coffey also discovered an overflow flaw in the RPC library used by
kadmind.  On Red Hat Enterprise Linux, exploitation of this flaw is limited
to a denial of service.  A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash. (CVE-2007-2443)

A stack buffer overflow flaw was found in kadmind.  An authenticated
attacker who can access kadmind could trigger this flaw and potentially
execute arbitrary code on the Kerberos server. (CVE-2007-2798)

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-26" />
        <updated date="2007-06-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2442.html">CVE-2007-2442</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2443.html">CVE-2007-2443</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2798.html">CVE-2007-2798</cve>
                <bugzilla href="http://bugzilla.redhat.com/245547" id="245547">CVE-2007-2442 krb5 RPC library unitialized pointer free</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245548" id="245548">CVE-2007-2443 krb5 RPC library stack overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245549" id="245549">CVE-2007-2798 krb5 kadmind buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562008" comment="krb5-libs is earlier than 0:1.5-26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095007" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562004" comment="krb5-devel is earlier than 0:1.5-26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095009" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562010" comment="krb5-server is earlier than 0:1.5-26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095011" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562002" comment="krb5 is earlier than 0:1.5-26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562006" comment="krb5-workstation is earlier than 0:1.5-26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562019" comment="krb5-libs is earlier than 0:1.3.4-49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095016" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562017" comment="krb5-devel is earlier than 0:1.3.4-49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095020" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562021" comment="krb5-server is earlier than 0:1.3.4-49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095022" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562013" comment="krb5 is earlier than 0:1.3.4-49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095014" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070562015" comment="krb5-workstation is earlier than 0:1.3.4-49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095018" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070569" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0569: tomcat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0569.html" />
          <reference source="CVE" ref_id="CVE-2007-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2449.html" />
          <reference source="CVE" ref_id="CVE-2007-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2450.html" />
    
    <description>Tomcat is a servlet container for Java Servlet and JavaServer Pages (JSP)
technologies.

Some JSPs within the 'examples' web application did not escape user
provided data. If the JSP examples were accessible, this flaw could allow a
remote attacker to perform cross-site scripting attacks (CVE-2007-2449).

Note: it is recommended the 'examples' web application not be installed on
a production system.

The Manager and Host Manager web applications did not escape user provided
data. If a user is logged in to the Manager or Host Manager web
application, an attacker could perform a cross-site scripting attack
(CVE-2007-2450).

Users of Tomcat should update to these erratum packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-17" />
        <updated date="2007-07-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2449.html">CVE-2007-2449</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2450.html">CVE-2007-2450</cve>
                <bugzilla href="http://bugzilla.redhat.com/244804" id="244804">CVE-2007-2449 tomcat examples jsp XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244808" id="244808">CVE-2007-2450 tomcat host manager XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244846" id="244846">/var/tmp/rpm-tmp.25596: line 5: /usr/bin/rebuild-gcj-db: No such file or directory</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569016" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327007" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569010" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327017" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569020" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327015" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569014" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327013" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569018" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327009" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569006" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327011" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569004" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327025" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569012" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327019" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569022" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327023" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569008" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327021" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070569002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.1.0.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327005" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070595" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0595: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0595-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0595.html" />
          <reference source="CVE" ref_id="CVE-2007-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3107.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain a fix for the following security issue:

* a flaw in the signal handling on PowerPC-based systems that allowed a
local user to cause a denial of service (floating point corruption).
(CVE-2007-3107, Moderate).

In addition to the security issue described above, a fix for the following
have been included:

* a bug that can lead to data corruption with ServerWorks IDE controllers.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-10" />
        <updated date="2007-07-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3107.html">CVE-2007-3107</cve>
                <bugzilla href="http://bugzilla.redhat.com/245580" id="245580">CVE-2007-3107 Data buffer miscompare on PowerPC when running HTX</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595004" comment="kernel-headers is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595002" comment="kernel is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595020" comment="kernel-doc is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595010" comment="kernel-devel is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595014" comment="kernel-kdump is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595008" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595012" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070595006" comment="kernel-xen is earlier than 0:2.6.18-8.1.8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070605" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0605: HelixPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0605-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0605.html" />
          <reference source="CVE" ref_id="CVE-2007-3410" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3410.html" />
    
    <description>HelixPlayer is a media player.

A buffer overflow flaw was found in the way HelixPlayer processed
Synchronized Multimedia Integration Language (SMIL) files. It was possible
for a malformed SMIL file to execute arbitrary code with the permissions of
the user running HelixPlayer. (CVE-2007-3410)

All users of HelixPlayer are advised to upgrade to this updated package,
which contains a backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-27" />
        <updated date="2007-06-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3410.html">CVE-2007-3410</cve>
                <bugzilla href="http://bugzilla.redhat.com/245836" id="245836">CVE-2007-3410 RealPlayer/HelixPlayer buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070605002" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070605003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070605004" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.2.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070605003" comment="HelixPlayer is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070631" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0631: coolkey security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0631-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0631.html" />
          <reference source="CVE" ref_id="CVE-2007-4129" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4129.html" />
    
    <description>coolkey contains the driver support for the CoolKey and Common Access Card
(CAC) Smart Card products. The CAC is used by the U.S. Government.

Steve Grubb discovered a flaw in the way coolkey created a temporary
directory. A local attacker could perform a symlink attack and cause
arbitrary files to be overwritten. (CVE-2007-4129)

In addition, the updated packages contain fixes for the following bugs in
the CAC Smart Card support:

* CAC Smart Cards can have from 1 to 3 certificates. The coolkey driver,
however, was not recognizing cards if they had less than 3 certificates.

* logging into a CAC Smart Card token with a new application would cause
other, already authenticated, applications to lose their login status
unless the Smart Card was then removed from the reader and re-inserted.

All CAC users should upgrade to these updated packages, which resolve these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4129.html">CVE-2007-4129</cve>
                <bugzilla href="http://bugzilla.redhat.com/200295" id="200295">Coolkey does not support CAC cards with less than 3 certs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/200316" id="200316">Open apps loose the CAC card after a C_logout from another app.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251774" id="251774">CVE-2007-4129 coolkey file and directory permission flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070631002" comment="coolkey is earlier than 0:1.1.0-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070631003" comment="coolkey is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070631004" comment="coolkey-devel is earlier than 0:1.1.0-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070631005" comment="coolkey-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070640" version="506" class="patch">
      <metadata>
        <title>RHSA-2007:0640: conga security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0640-05" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0640.html" />
          <reference source="CVE" ref_id="CVE-2007-4136" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4136.html" />
    
    <description>The Conga package is a web-based administration tool for remote cluster and
storage management.

A flaw was found in ricci during a code audit.  A remote attacker who is
able to connect to ricci could cause ricci to temporarily refuse additional
connections, a denial of service (CVE-2007-4136).

Fixes in this updated package include:

* The nodename is now set for manual fencing.

* The node log no longer displays in random order.

* A bug that prevented a node from responding when a cluster was deleted is
now fixed.

* A PAM configuration that incorrectly called the deprecated module
pam_stack was removed.

* A bug that prevented some quorum disk configurations from being accepted
is now fixed.

* Setting multicast addresses now works properly.

* rpm -V on luci no longer fails. 

* The user interface rendering time for storage interface is now faster.

* An error message that incorrectly appeared when rebooting nodes during
cluster creation was removed.

* Cluster snaps configuration (an unsupported feature) has been removed
altogether to prevent user confusion. 

* A user permission bug resulting from a luci code error is now fixed.

* luci and ricci init script return codes are now LSB-compliant.

* VG creation on cluster nodes now defaults to "clustered".

* An SELinux AVC bug that prevented users from setting up shared storage on
nodes is now fixed.

* An access error that occurred when attempting to access a cluster node
after its cluster was deleted is now fixed.

* IP addresses can now be used to create clusters. 

* Attempting to configure a fence device no longer results in an
AttributeError.

* Attempting to create a new fence device to a valid cluster no longer
results in a KeyError.

* Several minor user interface validation errors have been fixed, such as
enforcing cluster name length and fence port, etc.

* A browser lock-up that could occur during storage configuration has been
fixed.

* Virtual service creation now works without error.

* The fence_xvm tag is no longer misspelled in the cluster.conf file.

* Luci failover forms are complete and working.
* Rebooting a fresh cluster install no longer generates an error message.

* A bug that prevented failed cluster services from being started is now
fixed.

* A bug that caused some cluster operations (e.g., node delete) to fail on
clusters with mixed-cased cluster names is now fixed.

* Global cluster resources can be reused when constructing cluster
services.

Enhancements in this updated package include:

* Users can now access Conga through Internet Explorer 6.

* Dead nodes can now be evicted from a cluster.

* Shared storage on new clusters is now enabled by default.

* The fence user-interface flow is now simpler.

* A port number is now shown in ricci error messages.

* The kmod-gfs-xen kernel module is now installed when creating a cluster.

* Cluster creation status is now shown visually.

* User names are now sorted for display.

* The fence_xvmd tag can now be added from the dom0 cluster nodes.

* The ampersand character (&amp;) can now be used in fence names.

* All packaged files are now installed with proper owners and permissions.

* New cluster node members are now properly initialized.

* Storage operations can now be completed even if an LVM snapshot is present.

* Users are now informed via dialog when nodes are rebooted as part of a
cluster operation.

* Failover domains are now properly listed for virtual services and
traditional clustered services.

* Luci can now create and distribute keys for fence_xvmd.

All Conga users are advised to upgrade to this update, which applies these
fixes and enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4136.html">CVE-2007-4136</cve>
                <bugzilla href="http://bugzilla.redhat.com/212006" id="212006">create cluster does not show status as cluster is being created</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/212022" id="212022">cannot create cluster using ip addresses</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/213083" id="213083">luci - should display usernames in some logical/sorted order (usability)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/218964" id="218964">luci - adding node to a cluster - confirm dialog displays cluster name in place of node name (minor)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/221899" id="221899">Node log displayed in partially random order</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/222051" id="222051">Combining reauthentication/deletion options in one luci display can cause user confusion (usability - post RHEL5 GA)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/223162" id="223162">Error trying to create a new fence device for a cluster node</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/224011" id="224011">SELinux AVC denied  { read } for  pid=2390 comm="mdadm" - accessing storage on a node</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225164" id="225164">Conga allows creation/rename of clusters with name greater than 15 characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225206" id="225206">Cluster cannot be deleted (from 'Manage Systems') - but no error results</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225588" id="225588">luci web app does not enforce selection of fence port</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225747" id="225747">Create/delete cluster - then access disk on node = Generic error on host: cluster tools: cman_tool errored</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/225782" id="225782">Need more luci service information on startup - no info written to log about failed start cause</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/226700" id="226700">cman cluster needs restart when going from >=3 to 2 nodes and 2 to >= 3 nodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227682" id="227682">saslauthd[2274]: Deprecated pam_stack module called from service "ricci"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227743" id="227743">Intermittent/recurring problem - when cluster is deleted, sometimes a node is not affected</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227758" id="227758">Entering bad password when creating a new cluster = UnboundLocalError: local variable 'e' referenced before assignment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227852" id="227852">Lack of debugging information in logs - support issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229027" id="229027">luci failover domain forms are missing/empty</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230447" id="230447">fence_xvm is incorrectly listed as "xmv" in virtual cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230452" id="230452">Advanced options parameters settings don't do anything</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230454" id="230454">Unable to configure a virtual service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230457" id="230457">kmod-gfs-xen not installed with Conga install</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230461" id="230461">'enable shared storage' option cleared whenever there is a configuration error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230469" id="230469">Must manually edit cluster.conf on the dom0 cluster to add "&lt;fence_xvmd/>"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238655" id="238655">conga does not set the "nodename" attribute for manual fencing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/238726" id="238726">Conga provides no way to remove a dead node from a cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239327" id="239327">Online User Manual needs modification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239388" id="239388">conga storage: default VG creation should be clustered if a cluster node</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239389" id="239389">conga cluster: make 'enable shared storage' the default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240034" id="240034">rpm verify fails on luci</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240361" id="240361">Conga storage UI front-end is too slow rendering storage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241415" id="241415">Installation using Conga shows "error" in message during reboot cycle.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241418" id="241418">Conga tries to configurage cluster snaps, though they are not available.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241706" id="241706">Eliminate confusion in add fence flow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241727" id="241727">can't set user permissions in luci</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242668" id="242668">luci init script can return non-LSB-compliant return codes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243701" id="243701">ricci init script can exit with non-LSB-compliant return codes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244146" id="244146">Add port number to message when ricci is not started/firewalled on cluster nodes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244878" id="244878">Successful login results in an infinite redirection loop with MSIE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245202" id="245202">Conga needs to support Internet Explorer 6.0 and later</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248317" id="248317">luci sets incorrect permissions on /usr/lib64/luci and /var/lib/luci</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249066" id="249066">AttributeError when attempting to configure a fence device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249086" id="249086">Unable to add a new fence device to cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249091" id="249091">RFE: tell user they are about to kill all their nodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249291" id="249291">delete node task fails to do all items listed in the help document</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249641" id="249641">conga is unable to do storage operations if there is an lvm snapshot present</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249868" id="249868">Use of failover domain not correctly shown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250443" id="250443">storage name warning utility produces a storm of warnings which can lock your browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250834" id="250834">ZeroDivisionError when attempting to click an empty lvm volume group</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253914" id="253914">conga doesn't allow you to reuse nfs export and nfs client resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253994" id="253994">Cannot specify multicast address for a cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/254038" id="254038">Impossible to set many valid quorum disk configurations via conga</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/336101" id="336101">CVE-2007-4136 ricci is vulnerable to a connect DoS attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_cluster</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070640006" comment="ricci is earlier than 0:0.10.0-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070640007" comment="ricci is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070640004" comment="luci is earlier than 0:0.10.0-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070640005" comment="luci is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070640002" comment="conga is earlier than 0:0.10.0-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070640003" comment="conga is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070662" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0662: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0662-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0662.html" />
          <reference source="CVE" ref_id="CVE-2007-3304" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3304.html" />
    
    <description>The Apache HTTP Server is a popular Web server. 

The Apache HTTP Server did not verify that a process was an Apache child
process before sending it signals. A local attacker with the ability to run
scripts on the Apache HTTP Server could manipulate the scoreboard and cause
arbitrary processes to be terminated which could lead to a denial of
service.  (CVE-2007-3304).

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct this issue. Users should restart Apache
after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-13" />
        <updated date="2007-07-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3304.html">CVE-2007-3304</cve>
                <bugzilla href="http://bugzilla.redhat.com/245111" id="245111">CVE-2007-3304 httpd scoreboard lack of PID protection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662004" comment="httpd-devel is earlier than 0:2.0.46-68.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662006" comment="mod_ssl is earlier than 0:2.0.46-68.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662002" comment="httpd is earlier than 0:2.0.46-68.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662013" comment="httpd-manual is earlier than 0:2.0.52-32.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534005" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662015" comment="httpd-devel is earlier than 0:2.0.52-32.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662010" comment="httpd-suexec is earlier than 0:2.0.52-32.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662012" comment="mod_ssl is earlier than 0:2.0.52-32.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070662009" comment="httpd is earlier than 0:2.0.52-32.3.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070671" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0671: kernel security and bugfix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0671-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0671.html" />
          <reference source="CVE" ref_id="CVE-2007-1217" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1217.html" />
          <reference source="CVE" ref_id="CVE-2007-1353" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1353.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a
denial of service or potential privilege escalation. (CVE-2007-1217, Moderate)

* a flaw in the Bluetooth subsystem that allowed a local user to trigger an
information leak. (CVE-2007-1353, Low) 

In addition to the security issues described above, fixes for the following
have been included:

* a race condition in the e1000 network driver that could cause ESB2
systems to be started without the RX unit being turned on. 

* a related e1000 bug on ESB2 systems that could cause rlogin to fail.

Red Hat would like to thank Ilja van Sprundel for reporting an issue fixed
in this erratum. 

Note: The kernel-unsupported package contains various drivers and modules
that are unsupported and therefore might contain security problems that
have not been addressed.

All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels
to the packages associated with their machine architecture and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-16" />
        <updated date="2007-08-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1217.html">CVE-2007-1217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1353.html">CVE-2007-1353</cve>
                <bugzilla href="http://bugzilla.redhat.com/231069" id="231069">CVE-2007-1217 Overflow in CAPI subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234294" id="234294">CVE-2007-1353 Bluetooth setsockopt() information leaks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671008" comment="kernel-source is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671002" comment="kernel is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671004" comment="kernel-doc is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671016" comment="kernel-hugemem is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671014" comment="kernel-BOOT is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436013" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671012" comment="kernel-unsupported is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070671006" comment="kernel-smp is earlier than 0:2.4.21-51.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070674" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0674: perl-Net-DNS security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0674-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0674.html" />
          <reference source="CVE" ref_id="CVE-2007-3377" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3377.html" />
          <reference source="CVE" ref_id="CVE-2007-3409" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3409.html" />
    
    <description>Net::DNS is a collection of Perl modules that act as a Domain Name System
(DNS) resolver.

A flaw was found in the way Net::DNS generated the ID field in a DNS query.
This predictable ID field could be used by a remote attacker to return
invalid DNS data. (CVE-2007-3377)

A denial of service flaw was found in the way Net::DNS parsed certain DNS
requests. A malformed response to a DNS request could cause the application
using Net::DNS to crash or stop responding. (CVE-2007-3409)

Users of Net::DNS should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-07-12" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3377.html">CVE-2007-3377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3409.html">CVE-2007-3409</cve>
                <bugzilla href="http://bugzilla.redhat.com/245466" id="245466">CVE-2007-3377 perl-Net-DNS security issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245804" id="245804">CVE-2007-3409 Perl Net::DNS denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070674002" comment="perl-Net-DNS is earlier than 0:0.59-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070674003" comment="perl-Net-DNS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070674005" comment="perl-Net-DNS is earlier than 0:0.31-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070674006" comment="perl-Net-DNS is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070675" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0675: perl-Net-DNS security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0675-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0675.html" />
          <reference source="CVE" ref_id="CVE-2007-3377" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3377.html" />
    
    <description>Net::DNS is a collection of Perl modules that act as a Domain Name System
(DNS) resolver.

A flaw was found in the way Net::DNS generated the ID field in a DNS query.
This predictable ID field could be used by a remote attacker to return
invalid DNS data. (CVE-2007-3377)

Users of Net::DNS should upgrade to this updated package, which contains
backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-12" />
        <updated date="2007-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3377.html">CVE-2007-3377</cve>
                <bugzilla href="http://bugzilla.redhat.com/245466" id="245466">CVE-2007-3377 perl-Net-DNS security issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070675002" comment="perl-Net-DNS is earlier than 0:0.48-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070674006" comment="perl-Net-DNS is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070696" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0696: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0696-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0696.html" />
          <reference source="CVE" ref_id="CVE-2007-3456" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3456.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
browser plug-in.

An input validation flaw was found in the way Flash Player displayed
certain content. It may be possible to execute arbitrary code on a victim's
machine if the victim opens a malicious Adobe Flash file. (CVE-2007-3456)

Users of Adobe Flash Player should upgrade to this updated package, which
contains version 9.0.47.0. and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-12" />
        <updated date="2007-07-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3456.html">CVE-2007-3456</cve>
                <bugzilla href="http://bugzilla.redhat.com/247530" id="247530">CVE-2007-3456 flash-plugin input validation flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070696002" comment="flash-plugin is earlier than 0:9.0.48.0-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070696003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070701" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0701: xterm security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0701-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0701.html" />
          <reference source="CVE" ref_id="CVE-2007-2797" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2797.html" />
    
    <description>The xterm program is a terminal emulator for the X Window System. It
provides DEC VT102 and Tektronix 4014 compatible terminals for
programs that cannot use the window system directly.

A bug was found in the way xterm packages were built that caused the
pseudo-terminal device files of the xterm emulated terminals to be owned by
the incorrect group. This flaw did not affect Red Hat Enterprise Linux 4
Update 4 and earlier. (CVE-2007-2797)

All users of xterm are advised to upgrade to this updated package, which
contains a patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2797.html">CVE-2007-2797</cve>
                <bugzilla href="http://bugzilla.redhat.com/239070" id="239070">CVE-2007-2797 Wrong settings for the tty (mesg: error: tty device is not owned by group `tty')</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070701002" comment="xterm is earlier than 0:192-8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070701003" comment="xterm is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070703" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0703: openssh security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0703-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0703.html" />
          <reference source="CVE" ref_id="CVE-2006-5052" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5052.html" />
          <reference source="CVE" ref_id="CVE-2007-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3102.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the way the ssh server wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

A flaw was found in the way the OpenSSH server processes GSSAPI
authentication requests. When GSSAPI authentication was enabled in OpenSSH
server, a remote attacker may have been able to determine if a username is
valid. (CVE-2006-5052)

The following bugs were also fixed:

* the ssh daemon did not generate audit messages when an ssh session was
closed.

* GSSAPI authentication sometimes failed on clusters using DNS or
load-balancing.

* the sftp client and server leaked small amounts of memory in some cases.

* the sftp client didn't properly exit and return non-zero status in batch
mode when the destination disk drive was full.

* when restarting the ssh daemon with the initscript, the ssh daemon was
sometimes not restarted successfully because the old running ssh daemon was
not properly killed.

* with challenge/response authentication enabled, the pam sub-process was
not terminated if the user authentication timed out.

All users of openssh should upgrade to these updated packages, which
contain patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5052.html">CVE-2006-5052</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3102.html">CVE-2007-3102</cve>
                <bugzilla href="http://bugzilla.redhat.com/234643" id="234643">CVE-2006-5052 Kerberos information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240909" id="240909">memory leak fixed in RHEL3 but present in RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244655" id="244655">Trying to restart a hung/frozen sshd daemon doesn't show correct status</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247802" id="247802">sftp problem while transferring files to a partition which is 100% full</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248058" id="248058">CVE-2007-3102 audit logging of failed logins</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070703002" comment="openssh is earlier than 0:3.9p1-8.RHEL4.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257003" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070703008" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257009" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070703006" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257005" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070703004" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257007" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070703010" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070257011" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070705" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0705: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0705-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0705.html" />
          <reference source="CVE" ref_id="CVE-2007-1217" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1217.html" />
          <reference source="CVE" ref_id="CVE-2007-2875" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2875.html" />
          <reference source="CVE" ref_id="CVE-2007-2876" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2876.html" />
          <reference source="CVE" ref_id="CVE-2007-2878" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2878.html" />
          <reference source="CVE" ref_id="CVE-2007-3739" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3739.html" />
          <reference source="CVE" ref_id="CVE-2007-3740" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3740.html" />
          <reference source="CVE" ref_id="CVE-2007-3843" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3843.html" />
          <reference source="CVE" ref_id="CVE-2007-3851" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3851.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* a flaw in the DRM driver for Intel graphics cards that allowed a local
user to access any part of the main memory. To access the DRM functionality
a user must have access to the X server which is granted through the
graphical login. This also only affected systems with an Intel 965 or later
graphic chipset. (CVE-2007-3851, Important)

* a flaw in the VFAT compat ioctl handling on 64-bit systems that allowed a
local user to corrupt a kernel_dirent struct and cause a denial of service
(system crash). (CVE-2007-2878, Important)

* a flaw in the connection tracking support for SCTP that allowed a remote
user to cause a denial of service by dereferencing a NULL pointer.
(CVE-2007-2876, Important)

* flaw in the CIFS filesystem which could cause the umask values of a
process to not be honored. This affected CIFS filesystems where the Unix
extensions are supported. (CVE-2007-3740, Important)

* a flaw in the stack expansion when using the hugetlb kernel on PowerPC
systems that allowed a local user to cause a denial of service.
(CVE-2007-3739, Moderate)

* a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a
denial of service or potential remote access. Exploitation would require
the attacker to be able to send arbitrary frames over the ISDN network to
the victim's machine. (CVE-2007-1217, Moderate)

* a flaw in the cpuset support that allowed a local user to obtain
sensitive information from kernel memory. To exploit this the cpuset
filesystem would have to already be mounted. (CVE-2007-2875, Moderate)

* a flaw in the CIFS handling of the mount option "sec=" that didn't enable
integrity checking and didn't produce any error message. (CVE-2007-3843,
Low)

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-13" />
        <updated date="2007-09-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1217.html">CVE-2007-1217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2875.html">CVE-2007-2875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2876.html">CVE-2007-2876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2878.html">CVE-2007-2878</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3739.html">CVE-2007-3739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3740.html">CVE-2007-3740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3843.html">CVE-2007-3843</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3851.html">CVE-2007-3851</cve>
                <bugzilla href="http://bugzilla.redhat.com/232260" id="232260">CVE-2007-1217 Overflow in CAPI subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245773" id="245773">CVE-2007-2875 cpuset information leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245774" id="245774">CVE-2007-2876 {ip, nf}_conntrack_sctp: remotely triggerable NULL ptr dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247726" id="247726">CVE-2007-2878 VFAT compat ioctls DoS on 64-bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251185" id="251185">CVE-2007-3851 i965 DRM allows insecure packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253313" id="253313">CVE-2007-3739 LTC36188-Don't allow the stack to grow into hugetlb reserved regions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253314" id="253314">CVE-2007-3740 CIFS should honor umask</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253315" id="253315">CVE-2007-3843 CIFS signing sec= mount options don't work correctly</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705004" comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705002" comment="kernel is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705020" comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705006" comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705012" comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705008" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705014" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070705010" comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070709" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0709: wireshark security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0709-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0709.html" />
          <reference source="CVE" ref_id="CVE-2007-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3389.html" />
          <reference source="CVE" ref_id="CVE-2007-3390" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3390.html" />
          <reference source="CVE" ref_id="CVE-2007-3391" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3391.html" />
          <reference source="CVE" ref_id="CVE-2007-3392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3392.html" />
          <reference source="CVE" ref_id="CVE-2007-3393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3393.html" />
    
    <description>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's HTTP, iSeries, DCP
ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors. It was possible for
Wireshark to crash or stop responding if it read a malformed packet off the
network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392,
CVE-2007-3393)

Wireshark would interpret certain completion codes incorrectly when
dissecting IPMI traffic. Additionally, IPMI 2.0 packets would be reported
as malformed IPMI traffic.

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.6, which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3389.html">CVE-2007-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3390.html">CVE-2007-3390</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3391.html">CVE-2007-3391</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3392.html">CVE-2007-3392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3393.html">CVE-2007-3393</cve>
                <bugzilla href="http://bugzilla.redhat.com/245796" id="245796">CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245797" id="245797">CVE-2007-3391 Wireshark loops infinitely when inspecting DCP ETSI traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245798" id="245798">CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246221" id="246221">CVE-2007-3393 Wireshark corrupts the stack when inspecting BOOTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246225" id="246225">CVE-2007-3390 Wireshark crashes when inspecting iSeries traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246229" id="246229">CVE-2007-3392 Wireshark crashes when inspecting MMS traffic</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070709002" comment="wireshark is earlier than 0:0.99.6-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070709004" comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070710" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0710: wireshark security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0710-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0710.html" />
          <reference source="CVE" ref_id="CVE-2007-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3389.html" />
          <reference source="CVE" ref_id="CVE-2007-3390" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3390.html" />
          <reference source="CVE" ref_id="CVE-2007-3391" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3391.html" />
          <reference source="CVE" ref_id="CVE-2007-3392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3392.html" />
          <reference source="CVE" ref_id="CVE-2007-3393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3393.html" />
    
    <description>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's HTTP, iSeries, DCP
ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors.  It was possible for
Wireshark to crash or stop responding if it read a malformed packet off the
network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392,
CVE-2007-3393)

Users of Wireshark and Ethereal should upgrade to these updated packages,
containing Wireshark version 0.99.6, which is not vulnerable to these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3389.html">CVE-2007-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3390.html">CVE-2007-3390</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3391.html">CVE-2007-3391</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3392.html">CVE-2007-3392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3393.html">CVE-2007-3393</cve>
                <bugzilla href="http://bugzilla.redhat.com/245796" id="245796">CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245797" id="245797">CVE-2007-3391 Wireshark loops infinitely when inspecting DCP ETSI traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245798" id="245798">CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246221" id="246221">CVE-2007-3393 Wireshark corrupts the stack when inspecting BOOTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246225" id="246225">CVE-2007-3390 Wireshark crashes when inspecting iSeries traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246229" id="246229">CVE-2007-3392 Wireshark crashes when inspecting MMS traffic</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070710002" comment="wireshark is earlier than 0:0.99.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070710004" comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070066005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070720" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0720: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0720-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0720.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Maurycy Prodeus discovered an integer overflow flaw in the way CUPS processes
PDF files.  An attacker could create a malicious PDF file that could
potentially execute arbitrary code when printed.  (CVE-2007-3387)

All users of CUPS should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-07-30" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720004" comment="cups-lpd is earlier than 1:1.2.4-11.5.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123005" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720006" comment="cups-devel is earlier than 1:1.2.4-11.5.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123009" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720008" comment="cups-libs is earlier than 1:1.2.4-11.5.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123007" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720002" comment="cups is earlier than 1:1.2.4-11.5.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720013" comment="cups-devel is earlier than 1:1.1.17-13.3.45" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720015" comment="cups-libs is earlier than 1:1.1.17-13.3.45" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720011" comment="cups is earlier than 1:1.1.17-13.3.45" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720019" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720020" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070720018" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070721" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0721: qt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0721-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0721.html" />
          <reference source="CVE" ref_id="CVE-2007-3388" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3388.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

Several format string flaws were found in Qt error message handling.  If an
application linked against Qt created an error message from user supplied
data in a certain way, it could lead to a denial of service or possibly
allow the execution of arbitrary code. (CVE-2007-3388)

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct these issues.

Red Hat would like to acknowledge Tim Brown of Portcullis Computer
Security and Dirk Mueller for these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-31" />
        <updated date="2007-08-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3388.html">CVE-2007-3388</cve>
                <bugzilla href="http://bugzilla.redhat.com/248417" id="248417">CVE-2007-3388 qt3 format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721014" comment="qt-devel-docs is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721015" comment="qt-devel-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721004" comment="qt-ODBC is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721005" comment="qt-ODBC is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721008" comment="qt-designer is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721009" comment="qt-designer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721002" comment="qt is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721003" comment="qt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721006" comment="qt-config is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721007" comment="qt-config is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721012" comment="qt-MySQL is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721013" comment="qt-MySQL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721016" comment="qt-devel is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721017" comment="qt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721010" comment="qt-PostgreSQL is earlier than 1:3.3.6-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721011" comment="qt-PostgreSQL is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721031" comment="qt-ODBC is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721032" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721023" comment="qt-designer is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721024" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721019" comment="qt is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721020" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721029" comment="qt-config is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721030" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721027" comment="qt-MySQL is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721028" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721025" comment="qt-devel is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721026" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721021" comment="qt-PostgreSQL is earlier than 1:3.1.2-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721022" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721040" comment="qt-ODBC is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721032" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721037" comment="qt-designer is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721024" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721034" comment="qt is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721020" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721039" comment="qt-config is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721030" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721036" comment="qt-MySQL is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721028" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721035" comment="qt-devel is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721026" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070721038" comment="qt-PostgreSQL is earlier than 1:3.3.3-11.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721022" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070722" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0722: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0722-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0722.html" />
          <reference source="CVE" ref_id="CVE-2007-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3089.html" />
          <reference source="CVE" ref_id="CVE-2007-3656" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3656.html" />
          <reference source="CVE" ref_id="CVE-2007-3734" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3734.html" />
          <reference source="CVE" ref_id="CVE-2007-3735" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3735.html" />
          <reference source="CVE" ref_id="CVE-2007-3736" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3736.html" />
          <reference source="CVE" ref_id="CVE-2007-3737" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3737.html" />
          <reference source="CVE" ref_id="CVE-2007-3738" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3738.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause SeaMonkey to crash or potentially execute arbitrary code as the user
running SeaMonkey. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737, CVE-2007-3738)

Several content injection flaws were found in the way SeaMonkey handled
certain JavaScript code. A web page containing malicious JavaScript code
could inject arbitrary content into other web pages. (CVE-2007-3736,
CVE-2007-3089)

A flaw was found in the way SeaMonkey cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-3656)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-18" />
        <updated date="2007-07-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3089.html">CVE-2007-3089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3656.html">CVE-2007-3656</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3734.html">CVE-2007-3734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3735.html">CVE-2007-3735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3736.html">CVE-2007-3736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3737.html">CVE-2007-3737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3738.html">CVE-2007-3738</cve>
                <bugzilla href="http://bugzilla.redhat.com/248518" id="248518">CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722014" comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722020" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722012" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722006" comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722002" comment="seamonkey is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722018" comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722016" comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722010" comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722008" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722027" comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722031" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722026" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722032" comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722023" comment="seamonkey is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722030" comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722029" comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722025" comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722024" comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070722028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070723" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0723: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0723-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0723.html" />
          <reference source="CVE" ref_id="CVE-2007-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3089.html" />
          <reference source="CVE" ref_id="CVE-2007-3734" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3734.html" />
          <reference source="CVE" ref_id="CVE-2007-3735" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3735.html" />
          <reference source="CVE" ref_id="CVE-2007-3736" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3736.html" />
          <reference source="CVE" ref_id="CVE-2007-3737" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3737.html" />
          <reference source="CVE" ref_id="CVE-2007-3738" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3738.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way Thunderbird processed certain malformed
JavaScript code. A malicious HTML email message containing JavaScript code
could cause Thunderbird to crash or potentially execute arbitrary code as
the user running Thunderbird.  JavaScript support is disabled by default in
Thunderbird; these issues are not exploitable unless the user has enabled
JavaScript. (CVE-2007-3089, CVE-2007-3734, CVE-2007-3735, CVE-2007-3736,
CVE-2007-3737, CVE-2007-3738)

Users of Thunderbird are advised to upgrade to these erratum packages,
which contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-07-18" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3089.html">CVE-2007-3089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3734.html">CVE-2007-3734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3735.html">CVE-2007-3735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3736.html">CVE-2007-3736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3737.html">CVE-2007-3737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3738.html">CVE-2007-3738</cve>
                <bugzilla href="http://bugzilla.redhat.com/248518" id="248518">CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070723002" comment="thunderbird is earlier than 0:1.5.0.12-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070723005" comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070724" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0724: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0724-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0724.html" />
          <reference source="CVE" ref_id="CVE-2007-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3089.html" />
          <reference source="CVE" ref_id="CVE-2007-3656" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3656.html" />
          <reference source="CVE" ref_id="CVE-2007-3734" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3734.html" />
          <reference source="CVE" ref_id="CVE-2007-3735" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3735.html" />
          <reference source="CVE" ref_id="CVE-2007-3736" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3736.html" />
          <reference source="CVE" ref_id="CVE-2007-3737" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3737.html" />
          <reference source="CVE" ref_id="CVE-2007-3738" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3738.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed
JavaScript code. A web page containing malicious JavaScript code could
cause Firefox to crash or potentially execute arbitrary code as the user
running Firefox. (CVE-2007-3734, CVE-2007-3735, CVE-2007-3737, CVE-2007-3738)

Several content injection flaws were found in the way Firefox handled
certain JavaScript code. A web page containing malicious JavaScript code
could inject arbitrary content into other web pages. (CVE-2007-3736,
CVE-2007-3089)

A flaw was found in the way Firefox cached web pages on the local disk. A
malicious web page may be able to inject arbitrary HTML into a browsing
session if the user reloads a targeted site. (CVE-2007-3656)

Users of Firefox are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-07-18" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3089.html">CVE-2007-3089</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3656.html">CVE-2007-3656</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3734.html">CVE-2007-3734</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3735.html">CVE-2007-3735</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3736.html">CVE-2007-3736</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3737.html">CVE-2007-3737</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3738.html">CVE-2007-3738</cve>
                <bugzilla href="http://bugzilla.redhat.com/248518" id="248518">CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070724004" comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097011" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070724002" comment="firefox is earlier than 0:1.5.0.12-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070724007" comment="firefox is earlier than 0:1.5.0.12-0.3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070729" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0729: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0729-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0729.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
including kpdf, a PDF file viewer.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause kpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of kdegraphics should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-30" />
        <updated date="2007-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070729002" comment="kdegraphics is earlier than 7:3.5.4-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070729004" comment="kdegraphics-devel is earlier than 7:3.5.4-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070729007" comment="kdegraphics is earlier than 7:3.3.1-4.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729008" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070729009" comment="kdegraphics-devel is earlier than 7:3.3.1-4.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729010" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070730" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0730: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0730-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0730.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>gpdf is a GNOME based viewer for Portable Document Format (PDF) files. 

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause gpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of gpdf should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-30" />
        <updated date="2007-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070730002" comment="gpdf is earlier than 0:2.8.2-7.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070730003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070731" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0731: tetex security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0731-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0731.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input and creates a typesetter-independent .dvi
(DeVice Independent) file as output.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause TeTeX to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of TeTeX should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-01" />
        <updated date="2007-08-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731006" comment="tetex-xdvi is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731007" comment="tetex-xdvi is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731002" comment="tetex is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731003" comment="tetex is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731012" comment="tetex-fonts is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731013" comment="tetex-fonts is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731008" comment="tetex-doc is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731009" comment="tetex-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731004" comment="tetex-latex is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731005" comment="tetex-latex is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731010" comment="tetex-dvips is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731011" comment="tetex-dvips is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731014" comment="tetex-afm is earlier than 0:3.0-33.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731015" comment="tetex-afm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731025" comment="tetex-xdvi is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731026" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731017" comment="tetex is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731018" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731029" comment="tetex-fonts is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731030" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731023" comment="tetex-doc is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731024" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731019" comment="tetex-latex is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731020" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731021" comment="tetex-dvips is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731022" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731027" comment="tetex-afm is earlier than 0:1.0.7-67.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731028" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731035" comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731026" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731032" comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731018" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731033" comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731030" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731038" comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731020" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731034" comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731024" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731037" comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731022" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070731036" comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731028" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070732" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0732: poppler security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0732-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0732.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>Poppler is a PDF rendering library, used by applications such as evince.

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause an application linked with poppler to crash or potentially execute
arbitrary code when opened.  (CVE-2007-3387)

All users of poppler should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-30" />
        <updated date="2007-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070732006" comment="poppler-utils is earlier than 0:0.5.4-4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732007" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070732002" comment="poppler is earlier than 0:0.5.4-4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070732004" comment="poppler-devel is earlier than 0:0.5.4-4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732005" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070735" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0735: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0735-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0735.html" />
          <reference source="CVE" ref_id="CVE-2007-3387" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3387.html" />
    
    <description>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files. 

Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files.  An attacker could create a malicious PDF file that would
cause Xpdf to crash or potentially execute arbitrary code when opened. 
(CVE-2007-3387)

All users of Xpdf should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-30" />
        <updated date="2007-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3387.html">CVE-2007-3387</cve>
                <bugzilla href="http://bugzilla.redhat.com/248194" id="248194">CVE-2007-3387 xpdf integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735002" comment="xpdf is earlier than 1:2.02-10.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735005" comment="xpdf is earlier than 1:3.00-12.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070737" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0737: pam security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0737-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0737.html" />
          <reference source="CVE" ref_id="CVE-2007-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1716.html" />
          <reference source="CVE" ref_id="CVE-2007-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3102.html" />
    
    <description>Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies without having to
recompile programs that handle authentication.

A flaw was found in the way pam_console set console device permissions. It
was possible for various console devices to retain ownership of the console
user after logging out, possibly leaking information to another local user.
(CVE-2007-1716)

A flaw was found in the way the PAM library wrote account names to the
audit subsystem. An attacker could inject strings containing parts of audit
messages, which could possibly mislead or confuse audit log parsing tools.
(CVE-2007-3102)

As well, these updated packages fix the following bugs:

* the pam_xauth module, which is used for copying the X11 authentication
cookie, did not reset the "XAUTHORITY" variable in certain circumstances,
causing unnecessary delays when using su command.

* when calculating password similarity, pam_cracklib disregarded changes
to the last character in passwords when "difok=x" (where "x" is the
number of characters required to change) was configured in
"/etc/pam.d/system-auth". This resulted in password changes that should
have been successful to fail with the following error:

BAD PASSWORD: is too similar to the old one

This issue has been resolved in these updated packages.

* the pam_limits module, which provides setting up system resources limits
for user sessions, reset the nice priority of the user session to "0" if it
was not configured otherwise in the "/etc/security/limits.conf"
configuration file.

These updated packages add the following enhancement:

* a new PAM module, pam_tally2, which allows accounts to be locked after a
maximum number of failed log in attempts.

All users of PAM should upgrade to these updated packages, which resolve
these issues and add this enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1716.html">CVE-2007-1716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3102.html">CVE-2007-3102</cve>
                <bugzilla href="http://bugzilla.redhat.com/228980" id="228980">XAUTHORITY env var not reset on 'su -'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230823" id="230823">CVE-2007-1716 Ownership of devices not returned to root after logout from console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247797" id="247797">CVE-2007-3102 audit logging of failed logins</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/267201" id="267201">pam_cracklib.so disregards changes to last char when calculating similarity</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070737004" comment="pam-devel is earlier than 0:0.77-66.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465005" comment="pam-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070737002" comment="pam is earlier than 0:0.77-66.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070465003" comment="pam is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070740" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0740: bind security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0740-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0740.html" />
          <reference source="CVE" ref_id="CVE-2007-2926" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2926.html" />
    
    <description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. 

A flaw was found in the way BIND generates outbound DNS query ids. If an
attacker is able to acquire a finite set of query IDs, it becomes possible
to accurately predict future query IDs. Future query ID prediction may
allow an attacker to conduct a DNS cache poisoning attack, which can result
in the DNS server returning incorrect client query data. (CVE-2007-2926)

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-07-24" />
        <updated date="2007-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2926.html">CVE-2007-2926</cve>
                <bugzilla href="http://bugzilla.redhat.com/248851" id="248851">CVE-2007-2926 bind cryptographically weak query ids</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740016" comment="bind-chroot is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057005" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740012" comment="bind-libbind-devel is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057015" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740010" comment="bind-devel is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057007" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740006" comment="bind-utils is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057011" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740004" comment="bind-sdb is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057009" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740002" comment="bind is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740014" comment="bind-libs is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057017" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740008" comment="caching-nameserver is earlier than 30:9.3.3-9.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070057013" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740027" comment="bind-devel is earlier than 20:9.2.4-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740023" comment="bind-chroot is earlier than 20:9.2.4-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740021" comment="bind-utils is earlier than 20:9.2.4-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740019" comment="bind is earlier than 20:9.2.4-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740025" comment="bind-libs is earlier than 20:9.2.4-21.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740034" comment="bind-devel is earlier than 20:9.2.4-27.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740032" comment="bind-utils is earlier than 20:9.2.4-27.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740031" comment="bind-chroot is earlier than 20:9.2.4-27.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740030" comment="bind is earlier than 20:9.2.4-27.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070740033" comment="bind-libs is earlier than 20:9.2.4-27.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070746" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:0746: httpd security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0746-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0746.html" />
          <reference source="CVE" ref_id="CVE-2007-3847" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3847.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module. (CVE-2007-3847)

As well, these updated packages fix the following bugs:

* Set-Cookie headers with a status code of 3xx are not forwarded to
clients when the "ProxyErrorOverride" directive is enabled. These
responses are overridden at the proxy. Only the responses with status
codes of 4xx and 5xx are overridden in these updated packages.

* the default "/etc/logrotate.d/httpd" script incorrectly invoked the kill
command, instead of using the "/sbin/service httpd restart" command. If you
configured the httpd PID to be in a location other than
"/var/run/httpd.pid", the httpd logs failed to be rotated. This has been
resolved in these updated packages.

* the "ProxyTimeout" directive was not inherited across virtual host
definitions.

* the logresolve utility was unable to read lines longer the 1024 bytes.

This update adds the following enhancements:

* a new configuration option has been added, "ServerTokens Full-Release",
which adds the package release to the server version string, which is
returned in the "Server" response header.

* a new module has been added, mod_version, which allows configuration
files to be written containing sections, which are evaluated only if the
version of httpd used matches a specified condition.

Users of httpd are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3847.html">CVE-2007-3847</cve>
                <bugzilla href="http://bugzilla.redhat.com/240024" id="240024">Mod_proxy_http ProxyErrorOverride eating cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240857" id="240857">[RFE] Apache does not report patch level when scanned</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241680" id="241680">logrotate.d/httpd postrotate must use initscripts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245719" id="245719">mod_proxy configuration inheritance issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245763" id="245763">long lines incorrectly handled by Apache's logresolve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250731" id="250731">CVE-2007-3847 httpd out of bounds read</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070746004" comment="httpd-manual is earlier than 0:2.2.3-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556009" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070746008" comment="httpd-devel is earlier than 0:2.2.3-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556005" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070746006" comment="mod_ssl is earlier than 0:2.2.3-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556007" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070746002" comment="httpd is earlier than 0:2.2.3-11.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070556003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070747" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0747: httpd security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0747-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0747.html" />
          <reference source="CVE" ref_id="CVE-2007-3847" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3847.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module. (CVE-2007-3847)

As well, these updated packages fix the following bugs:

* the default "/etc/logrotate.d/httpd" script incorrectly invoked the kill
command, instead of using the "/sbin/service httpd restart" command. If you
configured the httpd PID to be in a location other than
"/var/run/httpd.pid", the httpd logs failed to be rotated. This has been
resolved in these updated packages.

* Set-Cookie headers with a status code of 3xx are not forwarded to
clients when the "ProxyErrorOverride" directive is enabled. These
responses are overridden at the proxy. Only the responses with status
codes of 4xx and 5xx are overridden in these updated packages.

* mod_proxy did not correctly handle percent-encoded characters (ie %20)
when configured as a reverse proxy.

* invalid HTTP status codes could be logged if output filters returned
errors.

* the "ProxyTimeout" directive was not inherited across virtual host
definitions.

* in some cases the Content-Length header was dropped from HEAD responses.
This resulted in certain sites not working correctly with mod_proxy, such
as www.windowsupdate.com.

This update adds the following enhancements:

* a new configuration option has been added, "ServerTokens Full-Release",
which adds the package release to the server version string, which is
returned in the "Server" response header.

* a new module has been added, mod_version, which allows configuration
files to be written containing sections, which are evaluated only if the
version of httpd used matches a specified condition.

Users of httpd are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3847.html">CVE-2007-3847</cve>
                <bugzilla href="http://bugzilla.redhat.com/173467" id="173467">windowsupdate.microsoft.com does not work with mod_proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/197915" id="197915">%>s incorrectly logs status code as 70007  - default handler returns output filter apr_status_t value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233254" id="233254">mod_proxy not handling percent chars in URLs correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240022" id="240022">Mod_proxy_http ProxyErrorOverride eating cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241407" id="241407">logrotate.d/httpd postrotate must use initscripts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242920" id="242920">Reverse Proxy Unexpected Timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248696" id="248696">Identify httpd version to configuration</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250731" id="250731">CVE-2007-3847 httpd out of bounds read</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070747010" comment="httpd-manual is earlier than 0:2.0.52-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534005" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070747006" comment="httpd-devel is earlier than 0:2.0.52-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070747004" comment="httpd-suexec is earlier than 0:2.0.52-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070534011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070747008" comment="mod_ssl is earlier than 0:2.0.52-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070747002" comment="httpd is earlier than 0:2.0.52-38.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070533003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070765" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0765: libgtop2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0765-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0765.html" />
          <reference source="CVE" ref_id="CVE-2007-0235" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0235.html" />
    
    <description>The libgtop2 package contains a library for obtaining information about a
running system, such as cpu, memory and disk usage; active processes; and
PIDs.

A flaw was found in the way libgtop2 handled long filenames mapped
into the address space of a process. An attacker could execute arbitrary
code on behalf of the user running gnome-system-monitor by executing a
process and mapping a file with a specially crafted name into the
processes' address space. (CVE-2007-0235)

This update also fixes the following bug:

* when a version of libgtop2 compiled to run on a 32-bit architecture was
used to inspect a process running in 64-bit mode, it failed to report
certain information regarding address space mapping correctly.

All users of gnome-system-monitor are advised to upgrade to this updated
libgtop2 package, which contains backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-07" />
        <updated date="2007-08-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0235.html">CVE-2007-0235</cve>
                <bugzilla href="http://bugzilla.redhat.com/208265" id="208265">LTC27411-bad PROC_MAPS_FORMAT in libgtop2-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249884" id="249884">CVE-2007-0235 Stack overflow libgtop when pathname of mmap()-ed file is too long</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070765002" comment="libgtop2 is earlier than 0:2.8.0-1.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070765003" comment="libgtop2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070765004" comment="libgtop2-devel is earlier than 0:2.8.0-1.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070765005" comment="libgtop2-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070774" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0774: kernel security and bugfix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0774-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0774.html" />
          <reference source="CVE" ref_id="CVE-2006-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0558.html" />
          <reference source="CVE" ref_id="CVE-2007-1217" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1217.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below:

* a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a
denial of service or potential remote access. Exploitation would require
the attacker to be able to send arbitrary frames over the ISDN network to
the victim's machine. (CVE-2007-1217, Moderate) 

* a flaw in the perfmon subsystem on ia64 platforms that allowed a local
user to cause a denial of service. (CVE-2006-0558, Moderate)

In addition, the following bugs were addressed:

* a panic after reloading of the LSI Fusion driver.

* a vm performance problem was corrected by balancing inactive page lists.

* added a nodirplus option to address NFSv3 performance issues with large
directories.

* changed the personality handling to disallow personality changes of
setuid and setgid binaries. This ensures they keep any randomization and
Exec-shield protection.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0558.html">CVE-2006-0558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1217.html">CVE-2007-1217</cve>
                <bugzilla href="http://bugzilla.redhat.com/243257" id="243257">CVE-2007-1217 Overflow in CAPI subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248141" id="248141">lockup in shrink_zone when node out of memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250199" id="250199">CVE-2006-0558 ia64 crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774002" comment="kernel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774022" comment="kernel-doc is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774004" comment="kernel-devel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774008" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774020" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774016" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774014" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488011" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774012" comment="kernel-xenU is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488009" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070774006" comment="kernel-smp is earlier than 0:2.6.9-55.0.6.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070777" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0777: gdm security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0777-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0777.html" />
          <reference source="CVE" ref_id="CVE-2007-3381" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3381.html" />
    
    <description>Gdm (the GNOME Display Manager) is a highly configurable reimplementation
of xdm, the X Display Manager. Gdm allows you to log into your system with
the X Window System running and supports running several different X
sessions on your local machine at the same time.

A flaw was found in the way Gdm listens on its unix domain socket.  A local
user could crash a running X session by writing malicious data to Gdm's
unix domain socket. (CVE-2007-3381)

All users of gdm should upgrade to this updated package, which contains a
backported patch that resolves this issue.

Red Hat would like to thank JLANTHEA for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-07" />
        <updated date="2007-08-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3381.html">CVE-2007-3381</cve>
                <bugzilla href="http://bugzilla.redhat.com/247655" id="247655">CVE-2007-3381 Gdm denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070777002" comment="gdm is earlier than 1:2.16.0-31.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070777003" comment="gdm is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070779" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0779: mailman security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0779-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0779.html" />
          <reference source="CVE" ref_id="CVE-2006-4624" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4624.html" />
    
    <description>Mailman is a program used to help manage email discussion lists.

A flaw was found in Mailman. A remote attacker could spoof messages in
the error log, and possibly trick the administrator into visiting malicious
URLs via a carriage return/line feed sequence in the URI. (CVE-2006-4624)

As well, these updated packages fix the following bugs:

* canceling a subscription on the confirm subscription request page
caused mailman to crash.

* editing the sender filter caused all spam filter rules to be deleted.

* the migrate-fhs script was not included.

* the mailman init script returned a zero (success) exit code even when
an incorrect command was given. For example, the "mailman foo" command
returned a zero exit code. In these updated packages the mailmain init
script returns the correct exit codes.

Users of Mailman are advised to upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4624.html">CVE-2006-4624</cve>
                <bugzilla href="http://bugzilla.redhat.com/200036" id="200036">Canceling subscription confirmation crashes mailman</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/205651" id="205651">CVE-2006-4624 mailman logfile CRLF injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/223191" id="223191">Spam filters gets deleted when sender filter is edited</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230939" id="230939">mailman-2.1.5.1-34.rhel4.5 is missing migrate-fhs script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242677" id="242677">Wrong init script</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070779002" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070779003" comment="mailman is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070795" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0795: cyrus-sasl security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0795-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0795.html" />
          <reference source="CVE" ref_id="CVE-2006-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1721.html" />
    
    <description>The cyrus-sasl package contains the Cyrus implementation of SASL. SASL is
the Simple Authentication and Security Layer, a method for adding
authentication support to connection-based protocols.

A bug was found in cyrus-sasl's DIGEST-MD5 authentication mechanism. As
part of the DIGEST-MD5 authentication exchange, the client is expected to
send a specific set of information to the server. If one of these items
(the "realm") was not sent or was malformed, it was possible for a remote
unauthenticated attacker to cause a denial of service (segmentation fault)
on the server. (CVE-2006-1721)

This errata also fixes the following bugs:

* the Kerberos 5 library included in Red Hat Enterprise Linux 4 was not
thread safe. This update adds functionality which allows it to be used
safely in a threaded application.

* several memory leak bugs were fixed in cyrus-sasl's DIGEST-MD5
authentication plug-in.

* /dev/urandom is now used by default on systems which don't support
hwrandom. Previously, dev/random was the default.

* cyrus-sasl needs zlib-devel to build properly. This dependency
information is now included in the package.

Users are advised to upgrade to this updated cyrus-sasl package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1721.html">CVE-2006-1721</cve>
                <bugzilla href="http://bugzilla.redhat.com/157012" id="157012">[RFE] cyrus-sasl should use /dev/urandom by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/189814" id="189814">CVE-2006-1721 cyrus-sasl digest-md5 DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/190113" id="190113">Missing build dependancy for zlib-devel in cyrus-sasl</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243910" id="243910">krb5-libs are not thread-safe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244075" id="244075">Memory leaks in digest-md5 plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250732" id="250732">sasl-sample-server crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795012" comment="cyrus-sasl-plain is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795013" comment="cyrus-sasl-plain is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795006" comment="cyrus-sasl-devel is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795007" comment="cyrus-sasl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795008" comment="cyrus-sasl-ntlm is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795009" comment="cyrus-sasl-ntlm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795004" comment="cyrus-sasl-md5 is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795005" comment="cyrus-sasl-md5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795010" comment="cyrus-sasl-gssapi is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795011" comment="cyrus-sasl-gssapi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795002" comment="cyrus-sasl is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795003" comment="cyrus-sasl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070795014" comment="cyrus-sasl-sql is earlier than 0:2.1.19-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795015" comment="cyrus-sasl-sql is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070813" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0813: openssl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0813-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0813.html" />
          <reference source="CVE" ref_id="CVE-2007-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3108.html" />
          <reference source="CVE" ref_id="CVE-2007-5135" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5135.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

A flaw was found in the SSL_get_shared_ciphers() utility function. An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer with a single byte (CVE-2007-5135). Few
applications make use of this vulnerable function and generally it is used
only when applications are compiled for debugging. 

A number of possible side-channel attacks were discovered affecting
OpenSSL. A local attacker could possibly obtain RSA private keys being
used on a system. In practice these attacks would be difficult to perform
outside of a lab environment. This update contains backported patches
designed to mitigate these issues.  (CVE-2007-3108).

Users of OpenSSL should upgrade to these updated packages, which contain
backported patches to resolve these issues.  

Note: After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-22" />
        <updated date="2007-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3108.html">CVE-2007-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5135.html">CVE-2007-5135</cve>
                <bugzilla href="http://bugzilla.redhat.com/245732" id="245732">CVE-2007-3108 openssl: RSA side-channel attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250573" id="250573">CVE-NONE openssl branch prediction attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/309801" id="309801">CVE-2007-5135 openssl SSL_get_shared_ciphers() off-by-one</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070813002" comment="openssl is earlier than 0:0.9.7a-33.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070813006" comment="openssl-perl is earlier than 0:0.9.7a-33.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070813004" comment="openssl-devel is earlier than 0:0.9.7a-33.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070817" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0817: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0817-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0817.html" />
          <reference source="CVE" ref_id="CVE-2007-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2435.html" />
          <reference source="CVE" ref_id="CVE-2007-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2788.html" />
          <reference source="CVE" ref_id="CVE-2007-2789" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2789.html" />
    
    <description>IBM's 1.4.2 SR9 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

A security vulnerability in the Java Web Start component was discovered. 
An untrusted application could elevate it's privileges and read and write
local files that are accessible to the user running the Java Web Start
application. (CVE-2007-2435)

A buffer overflow in the Java Runtime Environment image handling code was
found. An untrusted applet or application could use this flaw to elevate
its privileges and potentially execute arbitrary code as the user running
the java virtual machine. (CVE-2007-3004)

An unspecified vulnerability was discovered in the Java Runtime
Environment. An untrusted applet or application could cause the java
virtual machine to become unresponsive. (CVE-2007-3005)

All users of java-1.4.2-ibm should upgrade to these updated packages, 
which contain IBM's 1.4.2 SR9 Java release that resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-06" />
        <updated date="2007-08-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2435.html">CVE-2007-2435</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2788.html">CVE-2007-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2789.html">CVE-2007-2789</cve>
                <bugzilla href="http://bugzilla.redhat.com/239660" id="239660">CVE-2007-2435 javaws vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242595" id="242595">CVE-2007-3004 Integer overflow in IBM JDK's ICC profile parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250733" id="250733">CVE-2007-3005 Unspecified vulnerability in Sun JRE</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817008" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817010" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166011" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817006" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166009" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070817012" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.9-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070166013" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070829" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0829: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0829-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0829.html" />
          <reference source="CVE" ref_id="CVE-2007-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2435.html" />
          <reference source="CVE" ref_id="CVE-2007-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2788.html" />
          <reference source="CVE" ref_id="CVE-2007-2789" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2789.html" />
          <reference source="CVE" ref_id="CVE-2007-3503" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3503.html" />
          <reference source="CVE" ref_id="CVE-2007-3655" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3655.html" />
          <reference source="CVE" ref_id="CVE-2007-3922" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3922.html" />
          <reference source="CVE" ref_id="CVE-2007-4381" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4381.html" />
    
    <description>IBM's 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A security vulnerability in the Java Web Start component was discovered. An
untrusted application could elevate it's privileges, allowing it to read
and write local files that are accessible to the user running the Java Web
Start application. (CVE-2007-2435)

A buffer overflow in the Java Runtime Environment image handling code was
found. An untrusted applet or application could use this flaw to elevate
its privileges and potentially execute arbitrary code as the user running
the java virtual machine. (CVE-2007-2788, CVE-2007-2789, CVE-2007-3004)

An unspecified vulnerability was discovered in the Java Runtime
Environment. An untrusted applet or application could cause the java
virtual machine to become unresponsive. (CVE-2007-3005)

The Javadoc tool was able to generate HTML documentation pages that
contained cross-site scripting (XSS) vulnerabilities.  A remote attacker
could use this to inject arbitrary web script or HTML. (CVE-2007-3503)

The Java Web Start URL parsing component contains a buffer overflow
vulnerability within the parsing code for JNLP files. A remote attacker
could create a malicious JNLP file that could trigger this flaw and execute
arbitrary code when opened. (CVE-2007-3655)

A flaw was found in the applet class loader. An untrusted applet could use
this flaw to circumvent network access restrictions, possibly connecting
to services hosted on the machine that executed the applet. (CVE-2007-3922)

All users of java-ibm-1.5.0 should upgrade to these updated packages, which
contain IBM's 1.5.0 SR5a Java release that resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-07" />
        <updated date="2007-08-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2435.html">CVE-2007-2435</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2788.html">CVE-2007-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2789.html">CVE-2007-2789</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3503.html">CVE-2007-3503</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3655.html">CVE-2007-3655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3922.html">CVE-2007-3922</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4381.html">CVE-2007-4381</cve>
                <bugzilla href="http://bugzilla.redhat.com/239660" id="239660">CVE-2007-2435 javaws vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242595" id="242595">CVE-2007-3004 Integer overflow in IBM JDK's ICC profile parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246765" id="246765">CVE-2007-3503 HTML files generated with Javadoc are vulnerable to a XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248864" id="248864">CVE-2007-3655 A buffer overflow vulnerability in Java Web Start URL parsing code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249533" id="249533">CVE-2007-3922 Vulnerability in the Java Runtime Environment May Allow an Untrusted Applet to Circumvent Network Access Restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250725" id="250725">CVE-2007-2788 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250729" id="250729">CVE-2007-2789  BMP image parser vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250733" id="250733">CVE-2007-3005 Unspecified vulnerability in Sun JRE</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829008" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167013" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829014" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167011" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829010" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167009" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829006" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070829012" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.5-1jpp.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167007" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070845" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0845: libvorbis security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0845-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0845.html" />
          <reference source="CVE" ref_id="CVE-2007-3106" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3106.html" />
          <reference source="CVE" ref_id="CVE-2007-4029" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4029.html" />
          <reference source="CVE" ref_id="CVE-2007-4065" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4065.html" />
          <reference source="CVE" ref_id="CVE-2007-4066" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4066.html" />
    
    <description>The libvorbis package contains runtime libraries for use in programs that
support Ogg Voribs. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Several flaws were found in the way libvorbis processed audio data. An
attacker could create a carefully crafted OGG audio file in such a way that
it could cause an application linked with libvorbis to crash or execute
arbitrary code when it was opened. (CVE-2007-3106, CVE-2007-4029,
CVE-2007-4065, CVE-2007-4066)

Users of libvorbis are advised to upgrade to this updated package, which
contains backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-19" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3106.html">CVE-2007-3106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4029.html">CVE-2007-4029</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4065.html">CVE-2007-4065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4066.html">CVE-2007-4066</cve>
                <bugzilla href="http://bugzilla.redhat.com/245991" id="245991">CVE-2007-3106 libvorbis array boundary condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249780" id="249780">CVE-2007-4065 Multiple libvorbis flaws (CVE-2007-4066, CVE-2007-4029)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845004" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845005" comment="libvorbis-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845002" comment="libvorbis is earlier than 1:1.1.2-3.el5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845003" comment="libvorbis is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845009" comment="libvorbis-devel is earlier than 1:1.0-8.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845007" comment="libvorbis is earlier than 1:1.0-8.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845013" comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070845012" comment="libvorbis is earlier than 1:1.1.0-2.el4.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070845008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070848" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0848: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0848-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0848.html" />
          <reference source="CVE" ref_id="CVE-2007-2834" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2834.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the TIFF parser.  An attacker could
create a carefully crafted document containing a malicious TIFF file that
could cause OpenOffice.org to crash or possibly execute arbitrary code if
opened by a victim. (CVE-2007-2834)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-18" />
        <updated date="2007-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2834.html">CVE-2007-2834</cve>
                <bugzilla href="http://bugzilla.redhat.com/251967" id="251967">CVE-2007-2834 openoffice.org TIFF parsing heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848002" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848052" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069061" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848110" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069131" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848056" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069093" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848148" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069037" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848108" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069081" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848130" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069143" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848118" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069041" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848132" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069017" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848044" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069059" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848100" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069113" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848142" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069083" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848010" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069077" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848072" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069137" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848068" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069011" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848128" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069097" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848116" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069031" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848122" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069091" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848006" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069119" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848102" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069141" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848020" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069023" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848106" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069049" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848120" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069053" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848040" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069021" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848124" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069013" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848046" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069135" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848082" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069149" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848026" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069127" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848146" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069109" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848022" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069115" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848070" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069139" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848012" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069057" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848066" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069099" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848016" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069107" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848054" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069125" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848114" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069025" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848096" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069045" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848024" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069015" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848062" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069101" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848104" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069007" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848008" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069117" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848034" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069063" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848058" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069087" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848060" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069029" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848086" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069095" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848136" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069111" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848028" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069043" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848032" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069105" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848014" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069085" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848042" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069071" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848018" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069035" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848076" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069103" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848084" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069065" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848094" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069073" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848134" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069123" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848030" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069145" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848004" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848080" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069075" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848090" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069005" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848036" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069067" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848112" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069047" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848140" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069009" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848064" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069079" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848088" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069051" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848038" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069055" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848078" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069039" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848126" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069089" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848098" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069147" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848048" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069027" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848144" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069069" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848138" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069019" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848092" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069129" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848050" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069133" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848074" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069121" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848153" comment="openoffice.org-i18n is earlier than 0:1.1.2-40.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848151" comment="openoffice.org is earlier than 0:1.1.2-40.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848155" comment="openoffice.org-libs is earlier than 0:1.1.2-40.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848162" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.2.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848158" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.2.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848161" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.2.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848159" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.2.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848275" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406208" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848269" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406198" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848267" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406196" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848235" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406234" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848221" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406188" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848205" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406254" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848199" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406172" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848165" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406246" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848259" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406166" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848257" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406224" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848253" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406212" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848181" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406256" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848175" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406248" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848271" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406216" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848247" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406278" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848191" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406190" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848273" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406266" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848243" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406192" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848231" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406178" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848241" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406194" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848163" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406164" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848279" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406250" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848261" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406236" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848251" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406274" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848245" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406264" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848233" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406260" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848227" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406186" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848225" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406174" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848223" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406210" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848207" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406228" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848197" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406280" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848187" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406258" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848183" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406270" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848211" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406180" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848195" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406200" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848189" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406202" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848179" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406214" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848177" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406252" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848277" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406244" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848255" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406184" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848239" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406238" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848237" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406204" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848215" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406242" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848185" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406262" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848173" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406222" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848169" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406170" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848217" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406176" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848201" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406230" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848193" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406220" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848167" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406276" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848265" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406272" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848249" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406206" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848229" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406232" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848219" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406226" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848213" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406168" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848209" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406268" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848203" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406240" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848171" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406218" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070848263" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.2.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406182" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070858" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0858: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0858-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0858.html" />
          <reference source="CVE" ref_id="CVE-2007-3999" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3999.html" />
          <reference source="CVE" ref_id="CVE-2007-4000" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4000.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by kadmind.   A remote unauthenticated attacker who can access
kadmind could trigger this flaw and cause kadmind to crash.  On Red Hat
Enterprise Linux 5 it is not possible to exploit this flaw to run arbitrary
code as the overflow is blocked by FORTIFY_SOURCE.  (CVE-2007-3999)

Garrett Wollman discovered an uninitialized pointer flaw in kadmind.  A
remote unauthenticated attacker who can access kadmind could trigger this
flaw and cause kadmind to crash.  (CVE-2007-4000)

These issues did not affect the versions of Kerberos distributed with Red
Hat Enterprise Linux 2.1, 3, or 4.

Users of krb5-server are advised to update to these erratum packages which
contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2007-09-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3999.html">CVE-2007-3999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4000.html">CVE-2007-4000</cve>
                <bugzilla href="http://bugzilla.redhat.com/250973" id="250973">CVE-2007-3999 krb5 RPC library buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250976" id="250976">CVE-2007-4000 krb5 kadmind uninitialized pointer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858010" comment="krb5-libs is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095007" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858004" comment="krb5-devel is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095009" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858006" comment="krb5-server is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095011" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858002" comment="krb5 is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858008" comment="krb5-workstation is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070860" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0860: tar security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0860-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0860.html" />
          <reference source="CVE" ref_id="CVE-2007-4131" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4131.html" />
    
    <description>The GNU tar program saves many files together in one archive and can
restore individual files (or all of the files) from that archive. 

A path traversal flaw was discovered in the way GNU tar extracted archives.
A malicious user could create a tar archive that could write to arbitrary
files to which the user running GNU tar had write access. (CVE-2007-4131)

Red Hat would like to thank Dmitry V. Levin for reporting this issue.

Users of tar should upgrade to this updated package, which contains a
replacement backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-23" />
        <updated date="2007-08-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4131.html">CVE-2007-4131</cve>
                <bugzilla href="http://bugzilla.redhat.com/251921" id="251921">CVE-2007-4131 tar directory traversal vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070860002" comment="tar is earlier than 2:1.15.1-23.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070860003" comment="tar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070860005" comment="tar is earlier than 0:1.14-12.5.1.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070860006" comment="tar is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070871" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0871: tomcat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0871-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0871.html" />
          <reference source="CVE" ref_id="CVE-2007-3382" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3382.html" />
          <reference source="CVE" ref_id="CVE-2007-3385" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3385.html" />
          <reference source="CVE" ref_id="CVE-2007-3386" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3386.html" />
    
    <description>Tomcat is a servlet container for Java Servlet and Java Server Pages
technologies.

Tomcat was found treating single quote characters -- ' -- as delimiters in
cookies. This could allow remote attackers to obtain sensitive information,
such as session IDs, for session hijacking attacks (CVE-2007-3382).

It was reported Tomcat did not properly handle the following character
sequence in a cookie: \" (a backslash followed by a double-quote). It was
possible remote attackers could use this failure to obtain sensitive
information, such as session IDs, for session hijacking attacks
(CVE-2007-3385).

A cross-site scripting (XSS) vulnerability existed in the Host Manager
Servlet. This allowed remote attackers to inject arbitrary HTML and web
script via crafted requests (CVE-2007-3386).

Users of Tomcat should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-26" />
        <updated date="2007-09-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3382.html">CVE-2007-3382</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3385.html">CVE-2007-3385</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3386.html">CVE-2007-3386</cve>
                <bugzilla href="http://bugzilla.redhat.com/247972" id="247972">CVE-2007-3382 tomcat handling of cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247976" id="247976">CVE-2007-3385 tomcat handling of cookie values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247994" id="247994">CVE-2007-3386 tomcat host manager xss</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871020" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327007" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871016" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327017" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871018" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327015" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871022" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327013" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871008" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327009" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871010" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327011" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871014" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327025" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871012" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327019" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871006" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327023" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871004" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327021" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070871002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.3.0.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070327005" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070873" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0873: star security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0873-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0873.html" />
          <reference source="CVE" ref_id="CVE-2007-4134" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4134.html" />
    
    <description>Star is a tar-like archiver. It saves multiple files into a single tape or
disk archive, and can restore individual files from the archive. Star
includes multi-volume support, automatic archive format detection and ACL
support.

A path traversal flaw was discovered in the way star extracted archives. A
malicious user could create a tar archive that would cause star to write to
arbitrary files to which the user running star had write access.
(CVE-2007-4134)

Red Hat would like to thank Robert Buchholz for reporting this issue.

As well, this update adds the command line argument "-.." to the Red Hat
Enterprise Linux 3 version of star. This allows star to extract files
containing "/../" in their pathname.

Users of star should upgrade to this updated package, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2007-09-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4134.html">CVE-2007-4134</cve>
                <bugzilla href="http://bugzilla.redhat.com/253856" id="253856">CVE-2007-4134 star directory traversal vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873002" comment="star is earlier than 0:1.5a75-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873003" comment="star is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873005" comment="star is earlier than 0:1.5a08-5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873006" comment="star is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873008" comment="star is earlier than 0:1.5a25-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070873006" comment="star is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070875" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0875: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0875-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0875.html" />
          <reference source="CVE" ref_id="CVE-2007-3780" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3780.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld) and
many different client programs and libraries.

A flaw was discovered in MySQL's authentication protocol. It is possible
for a remote unauthenticated attacker to send a specially crafted
authentication request to the MySQL server causing it to crash. (CVE-2007-3780)

All users of the MySQL server are advised to upgrade to these updated
packages, which contain a backported patch which fixes this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-08-30" />
        <updated date="2007-08-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3780.html">CVE-2007-3780</cve>
                <bugzilla href="http://bugzilla.redhat.com/254108" id="254108">CVE-2007-3780 mysql malformed password crasher</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875010" comment="mysql-test is earlier than 0:5.0.22-2.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875011" comment="mysql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875002" comment="mysql is earlier than 0:5.0.22-2.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875003" comment="mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875006" comment="mysql-server is earlier than 0:5.0.22-2.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875007" comment="mysql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875008" comment="mysql-bench is earlier than 0:5.0.22-2.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875009" comment="mysql-bench is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875004" comment="mysql-devel is earlier than 0:5.0.22-2.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875005" comment="mysql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875013" comment="mysql is earlier than 0:4.1.20-2.RHEL4.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875017" comment="mysql-server is earlier than 0:4.1.20-2.RHEL4.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152009" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875019" comment="mysql-bench is earlier than 0:4.1.20-2.RHEL4.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152007" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070875015" comment="mysql-devel is earlier than 0:4.1.20-2.RHEL4.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152005" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070878" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0878: cyrus-sasl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0878-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0878.html" />
          <reference source="CVE" ref_id="CVE-2006-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1721.html" />
    
    <description>The cyrus-sasl package contains the Cyrus implementation of SASL.
SASL is the Simple Authentication and Security Layer, a method for
adding authentication support to connection-based protocols.

A bug was found in cyrus-sasl's DIGEST-MD5 authentication mechanism. As
part of the DIGEST-MD5 authentication exchange, the client is expected to
send a specific set of information to the server. If one of these items
(the "realm") was not sent or was malformed, it was possible for a remote
unauthenticated attacker to cause a denial of service (segmentation fault)
on the server. (CVE-2006-1721) 

Users of cyrus-sasl should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-09-04" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1721.html">CVE-2006-1721</cve>
                <bugzilla href="http://bugzilla.redhat.com/252339" id="252339">CVE-2006-1721 cyrus-sasl digest-md5 DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070878004" comment="cyrus-sasl-plain is earlier than 0:2.1.15-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795013" comment="cyrus-sasl-plain is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070878010" comment="cyrus-sasl-devel is earlier than 0:2.1.15-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795007" comment="cyrus-sasl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070878008" comment="cyrus-sasl-md5 is earlier than 0:2.1.15-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795005" comment="cyrus-sasl-md5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070878006" comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795011" comment="cyrus-sasl-gssapi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070878002" comment="cyrus-sasl is earlier than 0:2.1.15-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070795003" comment="cyrus-sasl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070883" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0883: qt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0883-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0883.html" />
          <reference source="CVE" ref_id="CVE-2007-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0242.html" />
          <reference source="CVE" ref_id="CVE-2007-4137" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4137.html" />
    
    <description>Qt is a software toolkit that simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications for the X Window
System.

A flaw was found in the way Qt expanded certain UTF8 characters. It was
possible to prevent a Qt-based application from properly sanitizing user
supplied input. This could, for example, result in a cross-site scripting
attack against the Konqueror web browser. (CVE-2007-0242)

A buffer overflow flaw was found in the way Qt expanded malformed Unicode
strings. If an application linked against Qt parsed a malicious Unicode
string, it could lead to a denial of service or possibly allow the
execution of arbitrary code. (CVE-2007-4137)

Users of Qt should upgrade to these updated packages, which contain a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-13" />
        <updated date="2007-09-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0242.html">CVE-2007-0242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4137.html">CVE-2007-4137</cve>
                <bugzilla href="http://bugzilla.redhat.com/234633" id="234633">CVE-2007-0242 QT UTF8 improper character expansion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/269001" id="269001">CVE-2007-4137 QT off by one buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883014" comment="qt-ODBC is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721005" comment="qt-ODBC is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883004" comment="qt-devel-docs is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721015" comment="qt-devel-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883012" comment="qt-designer is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721009" comment="qt-designer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883002" comment="qt is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721003" comment="qt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883016" comment="qt-config is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721007" comment="qt-config is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883008" comment="qt-MySQL is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721013" comment="qt-MySQL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883010" comment="qt-devel is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721017" comment="qt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883006" comment="qt-PostgreSQL is earlier than 1:3.3.6-23.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721011" comment="qt-PostgreSQL is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883029" comment="qt-ODBC is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721032" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883031" comment="qt-designer is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721024" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883019" comment="qt is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721020" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883025" comment="qt-config is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721030" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883023" comment="qt-MySQL is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721028" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883027" comment="qt-devel is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721026" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883021" comment="qt-PostgreSQL is earlier than 1:3.1.2-17.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721022" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883035" comment="qt-ODBC is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721032" comment="qt-ODBC is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883038" comment="qt-designer is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721024" comment="qt-designer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883034" comment="qt is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721020" comment="qt is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883036" comment="qt-config is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721030" comment="qt-config is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883037" comment="qt-MySQL is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721028" comment="qt-MySQL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883040" comment="qt-devel is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721026" comment="qt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070883039" comment="qt-PostgreSQL is earlier than 1:3.3.3-13.RHEL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070721022" comment="qt-PostgreSQL is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070889" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0889: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0889-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0889.html" />
          <reference source="CVE" ref_id="CVE-2007-2509" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2509.html" />
          <reference source="CVE" ref_id="CVE-2007-2756" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2756.html" />
          <reference source="CVE" ref_id="CVE-2007-2872" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2872.html" />
          <reference source="CVE" ref_id="CVE-2007-3799" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3799.html" />
          <reference source="CVE" ref_id="CVE-2007-3996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3996.html" />
          <reference source="CVE" ref_id="CVE-2007-3998" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3998.html" />
          <reference source="CVE" ref_id="CVE-2007-4658" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4658.html" />
          <reference source="CVE" ref_id="CVE-2007-4670" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4670.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

These updated packages address the following vulnerabilities:

Various integer overflow flaws were found in the PHP gd extension script
that could be forced to resize images from an untrusted source, possibly
allowing a remote attacker to execute arbitrary code as the apache
user. (CVE-2007-3996)

An integer overflow flaw was found in the PHP chunk_split function. If a
remote attacker was able to pass arbitrary data to the third argument of
chunk_split they could possibly execute arbitrary code as the apache user.
Note that it is unusual for a PHP script to use the chunk_split function
with a user-supplied third argument. (CVE-2007-2872)

A previous security update introduced a bug into PHP session cookie
handling. This could allow an attacker to stop a victim from viewing a
vulnerable web site if the victim has first visited a malicious web page
under the control of the attacker, and that page can set a cookie for the
vulnerable web site. (CVE-2007-4670)

A flaw was found in the PHP money_format function. If a remote attacker
was able to pass arbitrary data to the money_format function this could
possibly result in an information leak or denial of service. Note that it
is unusual for a PHP script to pass user-supplied data to the money_format
function. (CVE-2007-4658)

A flaw was found in the PHP wordwrap function. If a remote attacker was
able to pass arbitrary data to the wordwrap function this could possibly
result in a denial of service. (CVE-2007-3998)

A bug was found in PHP session cookie handling. This could allow an
attacker to create a cross-site cookie insertion attack if a victim follows
an untrusted carefully-crafted URL. (CVE-2007-3799)

An infinite-loop flaw was discovered in the PHP gd extension. A script
that could be forced to process PNG images from an untrusted source could
allow a remote attacker to cause a denial of service. (CVE-2007-2756)

A flaw was found in the PHP "ftp" extension. If a PHP script used this
extension to provide access to a private FTP server, and passed untrusted
script input directly to any function provided by this extension, a remote
attacker would be able to send arbitrary FTP commands to the server.
(CVE-2007-2509)

Users of PHP should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-26" />
        <updated date="2007-09-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2509.html">CVE-2007-2509</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2756.html">CVE-2007-2756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2872.html">CVE-2007-2872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3799.html">CVE-2007-3799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3996.html">CVE-2007-3996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3998.html">CVE-2007-3998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4658.html">CVE-2007-4658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4670.html">CVE-2007-4670</cve>
                <bugzilla href="http://bugzilla.redhat.com/239014" id="239014">CVE-2007-2509 php CRLF injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242032" id="242032">CVE-2007-2872 php chunk_split integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242033" id="242033">CVE-2007-2756 gd / php-gd ImageCreateFromPng infinite loop caused by truncated PNG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250726" id="250726">CVE-2007-3799 php cross-site cookie insertion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/276081" id="276081">CVE-2007-3998 php floating point exception inside wordwrap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278011" id="278011">CVE-2007-4658 php money_format format string issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278031" id="278031">CVE-2007-3996 php multiple integer overflows in gd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278041" id="278041">CVE-2007-4670 php malformed cookie handling</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889008" comment="php-odbc is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889014" comment="php-mysql is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889002" comment="php is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889010" comment="php-pgsql is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889004" comment="php-devel is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889012" comment="php-imap is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070889006" comment="php-ldap is earlier than 0:4.3.2-43.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070890" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0890: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0890-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0890.html" />
          <reference source="CVE" ref_id="CVE-2007-2756" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2756.html" />
          <reference source="CVE" ref_id="CVE-2007-2872" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2872.html" />
          <reference source="CVE" ref_id="CVE-2007-3799" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3799.html" />
          <reference source="CVE" ref_id="CVE-2007-3996" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3996.html" />
          <reference source="CVE" ref_id="CVE-2007-3998" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3998.html" />
          <reference source="CVE" ref_id="CVE-2007-4658" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4658.html" />
          <reference source="CVE" ref_id="CVE-2007-4670" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4670.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

Various integer overflow flaws were found in the PHP gd extension. A script
that could be forced to resize images from an untrusted source could
possibly allow a remote attacker to execute arbitrary code as the apache
user. (CVE-2007-3996)

An integer overflow flaw was found in the PHP chunk_split function. If a
remote attacker was able to pass arbitrary data to the third argument of
chunk_split they could possibly execute arbitrary code as the apache user.
Note that it is unusual for a PHP script to use the chunk_script function
with a user-supplied third argument. (CVE-2007-2872)

A previous security update introduced a bug into PHP session cookie
handling. This could allow an attacker to stop a victim from viewing a
vulnerable web site if the victim has first visited a malicious web page
under the control of the attacker, and that page can set a cookie for the
vulnerable web site. (CVE-2007-4670)

A flaw was found in the PHP money_format function. If a remote attacker
was able to pass arbitrary data to the money_format function this could
possibly result in an information leak or denial of service. Note that is
is unusual for a PHP script to pass user-supplied data to the money_format
function. (CVE-2007-4658)

A flaw was found in the PHP wordwrap function. If a remote attacker was
able to pass arbitrary data to the wordwrap function this could possibly
result in a denial of service. (CVE-2007-3998)

A bug was found in PHP session cookie handling. This could allow an
attacker to create a cross-site cookie insertion attack if a victim follows
an untrusted carefully-crafted URL. (CVE-2007-3799)

An infinite-loop flaw was discovered in the PHP gd extension. A script
that could be forced to process PNG images from an untrusted source could
allow a remote attacker to cause a denial of service. (CVE-2007-2756)

Users of PHP should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-20" />
        <updated date="2007-09-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2756.html">CVE-2007-2756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2872.html">CVE-2007-2872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3799.html">CVE-2007-3799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3996.html">CVE-2007-3996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3998.html">CVE-2007-3998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4658.html">CVE-2007-4658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4670.html">CVE-2007-4670</cve>
                <bugzilla href="http://bugzilla.redhat.com/242032" id="242032">CVE-2007-2872 php chunk_split integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242033" id="242033">CVE-2007-2756 gd / php-gd ImageCreateFromPng infinite loop caused by truncated PNG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250726" id="250726">CVE-2007-3799 php cross-site cookie insertion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/276081" id="276081">CVE-2007-3998 php floating point exception inside wordwrap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278011" id="278011">CVE-2007-4658 php money_format format string issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278031" id="278031">CVE-2007-3996 php multiple integer overflows in gd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278041" id="278041">CVE-2007-4670 php malformed cookie handling</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890038" comment="php-odbc is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082037" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890032" comment="php-common is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082009" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890012" comment="php-gd is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082035" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890006" comment="php-soap is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082015" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890018" comment="php-mysql is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082025" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890002" comment="php is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890008" comment="php-xmlrpc is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082005" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890030" comment="php-cli is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082019" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890022" comment="php-mbstring is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082033" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890026" comment="php-pgsql is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082023" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890016" comment="php-xml is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082039" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890036" comment="php-dba is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082007" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890028" comment="php-devel is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082021" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890020" comment="php-snmp is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082017" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890014" comment="php-imap is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082031" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890010" comment="php-ncurses is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082013" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890004" comment="php-bcmath is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082011" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890034" comment="php-ldap is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082029" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890024" comment="php-pdo is earlier than 0:5.1.6-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070082027" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890059" comment="php-odbc is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076007" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890053" comment="php-gd is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076036" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890061" comment="php-mysql is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890041" comment="php is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890055" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076024" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890049" comment="php-mbstring is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076022" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890063" comment="php-pgsql is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076005" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890057" comment="php-devel is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076009" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890067" comment="php-imap is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076015" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890065" comment="php-snmp is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076026" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890043" comment="php-ncurses is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076030" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890045" comment="php-pear is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076020" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890051" comment="php-ldap is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076013" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070890047" comment="php-domxml is earlier than 0:4.3.9-3.22.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070076028" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070892" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0892: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0892-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0892.html" />
          <reference source="CVE" ref_id="CVE-2007-4743" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4743.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.  kadmind is the KADM5 administration
server.

The MIT Kerberos Team discovered a problem with the originally published
patch for svc_auth_gss.c (CVE-2007-3999).  A remote unauthenticated
attacker who can access kadmind could trigger this flaw and cause kadmind
to crash.  On Red Hat Enterprise Linux 5 it is not possible to exploit this
flaw to run arbitrary code as the overflow is blocked by FORTIFY_SOURCE.
(CVE-2007-4743)

This issue did not affect the versions of Kerberos distributed with Red
Hat Enterprise Linux 2.1, 3, or 4.

Users of krb5-server are advised to update to these erratum packages which
contain a corrected backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-07" />
        <updated date="2007-09-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4743.html">CVE-2007-4743</cve>
                <bugzilla href="http://bugzilla.redhat.com/281561" id="281561">CVE-2007-4743 krb5 incomplete fix for CVE-2007-3999</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858010" comment="krb5-libs is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095007" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858004" comment="krb5-devel is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095009" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858006" comment="krb5-server is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095011" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858002" comment="krb5 is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070858008" comment="krb5-workstation is earlier than 0:1.5-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070095005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070898" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0898: xorg-x11 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0898-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0898.html" />
          <reference source="CVE" ref_id="CVE-2007-4730" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4730.html" />
    
    <description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way X.Org's composite extension handles 32 bit
color depth windows while running in 16 bit color depth mode. If an X.org
server has enabled the composite extension, it may be possible for a
malicious authorized client to cause a denial of service (crash) or
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-4730)

Please note this flaw can only be triggered when using a compositing window
manager. Red Hat Enterprise Linux 4 does not ship with a compositing window
manager.

Users of X.org should upgrade to these updated packages, which contain a
backported patch and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-19" />
        <updated date="2007-09-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4730.html">CVE-2007-4730</cve>
                <bugzilla href="http://bugzilla.redhat.com/285991" id="285991">CVE-2007-4730 X.org composite extension buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898034" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003023" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898024" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003027" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898022" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003015" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898036" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003007" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898032" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003037" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898026" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003009" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898020" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003005" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898008" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003013" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898012" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003021" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898004" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003029" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898030" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003035" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898028" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003033" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898018" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003025" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898006" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003031" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898016" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003019" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898014" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003017" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070898010" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.31" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070003011" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070905" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0905: kdebase security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0905-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0905.html" />
          <reference source="CVE" ref_id="CVE-2007-4569" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4569.html" />
          <reference source="CVE" ref_id="CVE-2007-3820" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3820.html" />
          <reference source="CVE" ref_id="CVE-2007-4224" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4224.html" />
    
    <description>The kdebase packages provide the core applications for KDE, the K Desktop
Environment. These core packages include Konqueror, the web browser and
file manager.

These updated packages address the following vulnerabilities:

Kees Huijgen found a flaw in the way KDM handled logins when autologin and
"shutdown with password" were enabled.  A local user would have been able
to login via KDM as any user without requiring a password. (CVE-2007-4569)

Two Konqueror address spoofing flaws were discovered. A malicious web site
could spoof the Konqueror address bar, tricking a victim into believing the
page was from a different site. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-08" />
        <updated date="2007-10-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4569.html">CVE-2007-4569</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3820.html">CVE-2007-3820</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4224.html">CVE-2007-4224</cve>
                <bugzilla href="http://bugzilla.redhat.com/248537" id="248537">CVE-2007-3820 Spoofing of URI possible in Konqueror's address bar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251708" id="251708">CVE-2007-4224 URL spoof in address bar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/287311" id="287311">CVE-2007-4569 kdm password-less login vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070905002" comment="kdebase is earlier than 6:3.5.4-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494003" comment="kdebase is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070905004" comment="kdebase-devel is earlier than 6:3.5.4-15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494005" comment="kdebase-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070905007" comment="kdebase is earlier than 6:3.3.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494008" comment="kdebase is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070905009" comment="kdebase-devel is earlier than 6:3.3.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070494010" comment="kdebase-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070909" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0909: kdelibs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0909-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0909.html" />
          <reference source="CVE" ref_id="CVE-2007-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0242.html" />
          <reference source="CVE" ref_id="CVE-2007-0537" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0537.html" />
          <reference source="CVE" ref_id="CVE-2007-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1308.html" />
          <reference source="CVE" ref_id="CVE-2007-1564" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1564.html" />
          <reference source="CVE" ref_id="CVE-2007-3820" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3820.html" />
          <reference source="CVE" ref_id="CVE-2007-4224" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4224.html" />
    
    <description>The kdelibs package provides libraries for the K Desktop Environment (KDE).

Two cross-site-scripting flaws were found in the way Konqueror processes
certain HTML content. This could result in a malicious attacker presenting
misleading content to an unsuspecting user. (CVE-2007-0242, CVE-2007-0537)

A flaw was found in KDE JavaScript implementation.  A web page containing
malicious JavaScript code could cause Konqueror to crash. (CVE-2007-1308)

A flaw was found in the way Konqueror handled certain FTP PASV commands.
A malicious FTP server could use this flaw to perform a rudimentary
port-scan of machines behind a user's firewall. (CVE-2007-1564)

Two Konqueror address spoofing flaws have been discovered. It was
possible for a malicious website to cause the Konqueror address bar to
display information which could trick a user into believing they are at a 
different website than they actually are. (CVE-2007-3820, CVE-2007-4224)

Users of KDE should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-10-08" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0242.html">CVE-2007-0242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0537.html">CVE-2007-0537</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1308.html">CVE-2007-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1564.html">CVE-2007-1564</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3820.html">CVE-2007-3820</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4224.html">CVE-2007-4224</cve>
                <bugzilla href="http://bugzilla.redhat.com/229606" id="229606">CVE-2007-0537 konqueror XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233592" id="233592">CVE-2007-1564 FTP protocol PASV design flaw affects konqueror</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/234633" id="234633">CVE-2007-0242 QT UTF8 improper character expansion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248537" id="248537">CVE-2007-3820 Spoofing of URI possible in Konqueror's address bar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251708" id="251708">CVE-2007-4224 URL spoof in address bar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/299891" id="299891">CVE-2007-1308 kdelibs KDE JavaScript denial of service (crash)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070909006" comment="kdelibs-apidocs is earlier than 6:3.5.4-13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070909007" comment="kdelibs-apidocs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070909002" comment="kdelibs is earlier than 6:3.5.4-13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070909003" comment="kdelibs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070909004" comment="kdelibs-devel is earlier than 6:3.5.4-13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070909005" comment="kdelibs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070909009" comment="kdelibs is earlier than 6:3.3.1-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070909010" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070909011" comment="kdelibs-devel is earlier than 6:3.3.1-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070909012" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070913" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0913: nfs-utils-lib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0913-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0913.html" />
          <reference source="CVE" ref_id="CVE-2007-3999" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3999.html" />
    
    <description>The nfs-utils-lib package contains support libraries that are needed by the
commands and daemons of the nfs-utils package.

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by nfs-utils-lib. A remote unauthenticated attacker who can
access an application linked against nfs-utils-lib could trigger this flaw
and cause the application to crash. On Red Hat Enterprise Linux 4 it is not
possible to exploit this flaw to run arbitrary code as the overflow is
blocked by FORTIFY_SOURCE. (CVE-2007-3999)

Users of nfs-utils-lib are advised to upgrade to this updated package,
which contains a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-19" />
        <updated date="2007-09-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3999.html">CVE-2007-3999</cve>
                <bugzilla href="http://bugzilla.redhat.com/250973" id="250973">CVE-2007-3999 krb5 RPC library buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070913002" comment="nfs-utils-lib is earlier than 0:1.0.6-8.z1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070913003" comment="nfs-utils-lib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070913004" comment="nfs-utils-lib-devel is earlier than 0:1.0.6-8.z1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070913005" comment="nfs-utils-lib-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070932" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0932: pwlib security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0932-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0932.html" />
          <reference source="CVE" ref_id="CVE-2007-4897" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4897.html" />
    
    <description>PWLib is a library used to support cross-platform applications.  

In Red Hat Enterprise Linux 5, the Ekiga teleconferencing application uses
PWLib.

A memory management flaw was discovered in PWLib.  An attacker could use this
flaw to crash an application, such as Ekiga, which is linked with pwlib
(CVE-2007-4897).  

Users should upgrade to these updated packages which contain a backported
patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-08" />
        <updated date="2007-10-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4897.html">CVE-2007-4897</cve>
                <bugzilla href="http://bugzilla.redhat.com/292831" id="292831">CVE-2007-4897 ekiga GetHostAddress remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070932002" comment="pwlib is earlier than 0:1.10.1-7.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070932003" comment="pwlib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070932004" comment="pwlib-devel is earlier than 0:1.10.1-7.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070932005" comment="pwlib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070933" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0933: elinks security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0933-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0933.html" />
          <reference source="CVE" ref_id="CVE-2007-5034" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5034.html" />
    
    <description>ELinks is a text mode Web browser used from the command line that supports
rendering modern web pages.

An information disclosure flaw was found in the way ELinks passes https
POST data to a proxy server. POST data sent via a proxy to an https site is
not properly encrypted by ELinks, possibly allowing the disclosure of
sensitive information. (CVE-2007-5034)

All users of Elinks are advised to upgrade to this updated package, which
contains a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-03" />
        <updated date="2007-10-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5034.html">CVE-2007-5034</cve>
                <bugzilla href="http://bugzilla.redhat.com/297611" id="297611">CVE-2007-5034 elinks reveals POST data to HTTPS proxy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070933002" comment="elinks is earlier than 0:0.11.1-5.1.0.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070933003" comment="elinks is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070933005" comment="elinks is earlier than 0:0.9.2-3.3.5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070933006" comment="elinks is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070936" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0936: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0936-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0936.html" />
          <reference source="CVE" ref_id="CVE-2007-4573" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4573.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw was found in the IA32 system call emulation provided on AMD64 and
Intel 64 platforms. An improperly validated 64-bit value could be stored in
the %RAX register, which could trigger an out-of-bounds system call table
access. An untrusted local user could exploit this flaw to run code in the
kernel (ie a root privilege escalation). (CVE-2007-4573).

Red Hat would like to thank Wojciech Purczynski for reporting this issue.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-27" />
        <updated date="2007-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4573.html">CVE-2007-4573</cve>
                <bugzilla href="http://bugzilla.redhat.com/294541" id="294541">CVE-2007-4573 x86_64 syscall vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936004" comment="kernel-headers is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936002" comment="kernel is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936020" comment="kernel-doc is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936016" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936010" comment="kernel-devel is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936012" comment="kernel-kdump is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936008" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936018" comment="kernel-PAE is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936014" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070936006" comment="kernel-xen is earlier than 0:2.6.18-8.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070937" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0937: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0937-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0937.html" />
          <reference source="CVE" ref_id="CVE-2007-4573" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4573.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw was found in the IA32 system call emulation provided on AMD64 and
Intel 64 platforms. An improperly validated 64-bit value could be stored in
the %RAX register, which could trigger an out-of-bounds system call table
access. An untrusted local user could exploit this flaw to run code in the
kernel (ie a root privilege escalation). (CVE-2007-4573).

Red Hat would like to thank Wojciech Purczynski for reporting this issue.

Red Hat Enterprise Linux 4 users are advised to upgrade to these packages,
which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-27" />
        <updated date="2007-09-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4573.html">CVE-2007-4573</cve>
                <bugzilla href="http://bugzilla.redhat.com/294541" id="294541">CVE-2007-4573 x86_64 syscall vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937002" comment="kernel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937022" comment="kernel-doc is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937004" comment="kernel-devel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937006" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937018" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937012" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937014" comment="kernel-xenU is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488009" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937008" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488011" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070937010" comment="kernel-smp is earlier than 0:2.6.9-55.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070938" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0938: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0938-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0938.html" />
          <reference source="CVE" ref_id="CVE-2007-4573" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4573.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

A flaw was found in ia32 emulation affecting users running 64-bit versions
of Red Hat Enterprise Linux on x86_64 architectures.  A local user could
use this flaw to gain elevated privileges. (CVE-2007-4573).   

Red Hat would like to thank Wojciech Purczynski for reporting this issue.

Red Hat Enterprise Linux 3 users are advised to upgrade to these packages,
which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-09-27" />
        <updated date="2007-11-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4573.html">CVE-2007-4573</cve>
                <bugzilla href="http://bugzilla.redhat.com/294541" id="294541">CVE-2007-4573 x86_64 syscall vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938008" comment="kernel-source is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938002" comment="kernel is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938004" comment="kernel-doc is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938016" comment="kernel-hugemem is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938014" comment="kernel-BOOT is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436013" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938012" comment="kernel-unsupported is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070938006" comment="kernel-smp is earlier than 0:2.4.21-52.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070939" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0939: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0939-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0939.html" />
          <reference source="CVE" ref_id="CVE-2006-6921" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6921.html" />
          <reference source="CVE" ref_id="CVE-2007-2878" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2878.html" />
          <reference source="CVE" ref_id="CVE-2007-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3105.html" />
          <reference source="CVE" ref_id="CVE-2007-3739" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3739.html" />
          <reference source="CVE" ref_id="CVE-2007-3740" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3740.html" />
          <reference source="CVE" ref_id="CVE-2007-3843" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3843.html" />
          <reference source="CVE" ref_id="CVE-2007-3848" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3848.html" />
          <reference source="CVE" ref_id="CVE-2007-4308" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4308.html" />
          <reference source="CVE" ref_id="CVE-2007-4571" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4571.html" />
    
    <description>The Linux kernel is the core of the operating system.

These updated kernel packages contain fixes for the following security
issues:

* A flaw was found in the handling of process death signals. This allowed a
local user to send arbitrary signals to the suid-process executed by that
user. A successful exploitation of this flaw depends on the structure of
the suid-program and its signal handling. (CVE-2007-3848, Important)

* A flaw was found in the CIFS file system. This could cause the umask
values of a process to not be honored on CIFS file systems where UNIX
extensions are supported. (CVE-2007-3740, Important)

* A flaw was found in the VFAT compat ioctl handling on 64-bit systems. 
This allowed a local user to corrupt a kernel_dirent struct and cause a
denial of service. (CVE-2007-2878, Important) 

* A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local
user who had the ability to read the /proc/driver/snd-page-alloc file could
see portions of kernel memory. (CVE-2007-4571, Moderate) 

* A flaw was found in the aacraid SCSI driver. This allowed a local user to
make ioctl calls to the driver that should be restricted to privileged
users. (CVE-2007-4308, Moderate) 

* A flaw was found in the stack expansion when using the hugetlb kernel on
PowerPC systems. This allowed a local user to cause a denial of service.
(CVE-2007-3739, Moderate) 

* A flaw was found in the handling of zombie processes. A local user could
create processes that would not be properly reaped which could lead to a
denial of service. (CVE-2006-6921, Moderate)

* A flaw was found in the CIFS file system handling. The mount option
"sec=" did not enable integrity checking or produce an error message if
used. (CVE-2007-3843, Low)

* A flaw was found in the random number generator implementation that
allowed a local user to cause a denial of service or possibly gain
privileges. This flaw could be exploited if the root user raised the
default wakeup threshold over the size of the output pool.
(CVE-2007-3105, Low)

Additionally, the following bugs were fixed:

* A flaw was found in the kernel netpoll code, creating a potential
deadlock condition.  If the xmit_lock for a given network interface is
held, and a subsequent netpoll event is generated from within the lock
owning context (a console message for example), deadlock on that cpu will
result, because the netpoll code will attempt to re-acquire the xmit_lock.
 The fix is to, in the netpoll code, only attempt to take the lock, and
fail if it is already acquired (rather than block on it), and queue the
message to be sent for later delivery.  Any user of netpoll code in the
kernel (netdump or netconsole services), is exposed to this problem, and
should resolve the issue by upgrading to this kernel release immediately.

* A flaw was found where, under 64-bit mode (x86_64), AMD processors were
not able to address greater than a 40-bit physical address space; and Intel
processors were only able to address up to a 36-bit physical address space. 
The fix is to increase the physical addressing for an AMD processor to 48
bits, and an Intel processor to 38 bits.  Please see the Red Hat
Knowledgebase for more detailed information.

* A flaw was found in the xenU kernel that may prevent a paravirtualized
guest with more than one CPU from starting when running under an Enterprise
Linux 5.1 hypervisor.  The fix is to allow your Enterprise Linux 4 Xen SMP
guests to boot under a 5.1 hypervisor. Please see the Red Hat Knowledgebase
for more detailed information.
 
Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-01" />
        <updated date="2007-11-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6921.html">CVE-2006-6921</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2878.html">CVE-2007-2878</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3105.html">CVE-2007-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3739.html">CVE-2007-3739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3740.html">CVE-2007-3740</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3843.html">CVE-2007-3843</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3848.html">CVE-2007-3848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4308.html">CVE-2007-4308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4571.html">CVE-2007-4571</cve>
                <bugzilla href="http://bugzilla.redhat.com/247726" id="247726">CVE-2007-2878 VFAT compat ioctls DoS on 64-bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248126" id="248126">autofs problem with symbolic links</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248325" id="248325">CVE-2007-3105 Bound check ordering issue in random driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250972" id="250972">CVE-2007-3848 Privilege escalation via PR_SET_PDEATHSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252309" id="252309">CVE-2007-4308 kernel: Missing ioctl() permission checks in aacraid driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/275881" id="275881">CVE-2007-3740 CIFS should honor umask</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/275901" id="275901">CVE-2007-3843 CIFS signing sec= mount options don't work correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/282351" id="282351">[PATCH] Fix memory leak of dma_alloc_coherent() on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/288961" id="288961">CVE-2007-4571 ALSA memory disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/294941" id="294941">CVE-2007-3739 LTC36188-Don't allow the stack to grow into hugetlb reserved regions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/302921" id="302921">CVE-2006-6921 kernel: denial of service with wedged processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/320791" id="320791">EL4.5: Improperly flushed TLBs may lead to Machine check errors</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939002" comment="kernel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939022" comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939004" comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939006" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939020" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939012" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939014" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488011" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939010" comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488009" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070939008" comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070940" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0940: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0940-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0940.html" />
          <reference source="CVE" ref_id="CVE-2007-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3105.html" />
          <reference source="CVE" ref_id="CVE-2007-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3380.html" />
          <reference source="CVE" ref_id="CVE-2007-3513" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3513.html" />
          <reference source="CVE" ref_id="CVE-2007-3731" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3731.html" />
          <reference source="CVE" ref_id="CVE-2007-3848" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3848.html" />
          <reference source="CVE" ref_id="CVE-2007-3850" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3850.html" />
          <reference source="CVE" ref_id="CVE-2007-4308" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4308.html" />
          <reference source="CVE" ref_id="CVE-2007-4133" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4133.html" />
          <reference source="CVE" ref_id="CVE-2007-4574" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4574.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

* A flaw was found in the backported stack unwinder fixes in Red Hat
Enterprise Linux 5.  On AMD64 and Intel 64 platforms, a local user could
trigger this flaw and cause a denial of service. (CVE-2007-4574, Important)

* A flaw was found in the handling of process death signals. This allowed a
local user to send arbitrary signals to the suid-process executed by that
user. A successful exploitation of this flaw depends on the structure of
the suid-program and its signal handling. (CVE-2007-3848, Important)

* A flaw was found in the Distributed Lock Manager (DLM) in the cluster
manager. This allowed a remote user who is able to connect to the DLM port
to cause a denial of service. (CVE-2007-3380, Important)

* A flaw was found in the aacraid SCSI driver. This allowed a local user to
make ioctl calls to the driver which should otherwise be restricted to
privileged users. (CVE-2007-4308, Moderate)

* A flaw was found in the prio_tree handling of the hugetlb support that
allowed a local user to cause a denial of service. This only affected
kernels with hugetlb support. (CVE-2007-4133, Moderate)

* A flaw was found in the eHCA driver on PowerPC architectures that allowed
a local user to access 60k of physical address space. This address space
could contain sensitive information. (CVE-2007-3850, Moderate)

* A flaw was found in ptrace support that allowed a local user to cause a
denial of service via a NULL pointer dereference. (CVE-2007-3731, Moderate)

* A flaw was found in the usblcd driver that allowed a local user to cause
a denial
of service by writing data to the device node. To exploit this issue, write
access to the device node was needed. (CVE-2007-3513, Moderate)

* A flaw was found in the random number generator implementation that
allowed a local user to cause a denial of service or possibly gain
privileges. If the root user raised the default wakeup threshold over the
size of the output pool, this flaw could be exploited. (CVE-2007-3105, Low)

In addition to the security issues described above, several bug fixes
preventing possible system crashes and data corruption were also included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-22" />
        <updated date="2007-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3105.html">CVE-2007-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3380.html">CVE-2007-3380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3513.html">CVE-2007-3513</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3731.html">CVE-2007-3731</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3848.html">CVE-2007-3848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3850.html">CVE-2007-3850</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4308.html">CVE-2007-4308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4133.html">CVE-2007-4133</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4574.html">CVE-2007-4574</cve>
                <bugzilla href="http://bugzilla.redhat.com/245922" id="245922">CVE-2007-3380 A TCP connection to DLM port blocks DLM operations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247728" id="247728">CVE-2007-3513 Locally triggerable memory consumption in usblcd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248324" id="248324">CVE-2007-3731 NULL pointer dereference triggered by ptrace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248325" id="248325">CVE-2007-3105 Bound check ordering issue in random driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250972" id="250972">CVE-2007-3848 Privilege escalation via PR_SET_PDEATHSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252309" id="252309">CVE-2007-4308 kernel: Missing ioctl() permission checks in aacraid driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253926" id="253926">CVE-2007-4133 prio_tree unit kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/298141" id="298141">CVE-2007-4574 EM64T local DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/308811" id="308811">CVE-2007-3850 kernel LTC31426-4k page mapping support for userspace in 64k kernels</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940004" comment="kernel-headers is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940002" comment="kernel is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940020" comment="kernel-doc is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940018" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940008" comment="kernel-devel is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940014" comment="kernel-kdump is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940010" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940016" comment="kernel-PAE is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940012" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070940006" comment="kernel-xen is earlier than 0:2.6.18-8.1.15.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070951" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0951: nfs-utils-lib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0951-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0951.html" />
          <reference source="CVE" ref_id="CVE-2007-3999" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3999.html" />
          <reference source="CVE" ref_id="CVE-2007-4135" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4135.html" />
    
    <description>The nfs-utils-lib package contains support libraries that are needed by the
commands and daemons of the nfs-utils package.

The updated nfs-utils package fixes the following vulnerabilities:

Tenable Network Security discovered a stack buffer overflow flaw in the RPC
library used by nfs-utils-lib. A remote unauthenticated attacker who can
access an application linked against nfs-utils-lib could trigger this flaw
and cause the application to crash. On Red Hat Enterprise Linux 5 it is not
possible to exploit this flaw to run arbitrary code as the overflow is
blocked by FORTIFY_SOURCE. (CVE-2007-3999)

Tony Ernst from SGI has discovered a flaw in the way nfsidmap maps NFSv4
unknown uids.  If an unknown user ID is encountered on an NFSv4 mounted
filesystem, the files will default to being owned by 'root' rather than
'nobody'. (CVE-2007-4135)

Users of nfs-utils-lib are advised to upgrade to this updated package,
which contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-02" />
        <updated date="2007-10-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3999.html">CVE-2007-3999</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4135.html">CVE-2007-4135</cve>
                <bugzilla href="http://bugzilla.redhat.com/250973" id="250973">CVE-2007-3999 krb5 RPC library buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/254040" id="254040">CVE-2007-4135 nfs-utils-lib NFSv4 user id mapping flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070951002" comment="nfs-utils-lib is earlier than 0:1.0.8-7.2.z2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070951003" comment="nfs-utils-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070951004" comment="nfs-utils-lib-devel is earlier than 0:1.0.8-7.2.z2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070951005" comment="nfs-utils-lib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070956" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0956: java-1.5.0-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0956-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0956.html" />
          <reference source="CVE" ref_id="CVE-2007-0243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0243.html" />
          <reference source="CVE" ref_id="CVE-2007-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2788.html" />
          <reference source="CVE" ref_id="CVE-2007-2789" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2789.html" />
          <reference source="CVE" ref_id="CVE-2007-3503" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3503.html" />
          <reference source="CVE" ref_id="CVE-2007-3698" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3698.html" />
          <reference source="CVE" ref_id="CVE-2007-4381" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4381.html" />
    
    <description>The BEA WebLogic JRockit 1.5.0_11 JRE and SDK contain BEA WebLogic JRockit
Virtual Machine 1.5.0_11 and are certified for the Java 5 Platform,
Standard Edition, v1.5.0.

A flaw was found in the BEA Java Runtime Environment GIF image handling. 
If an application processes untrusted GIF image input, it may be possible
to execute arbitrary code as the user running the Java Virtual Machine. 
(CVE-2007-0243)

A buffer overflow in the Java Runtime Environment image handling code was
found. If an attacker is able to cause a server application to process a
specially crafted image file, it may be possible to execute arbitrary code
as the user running the Java Virtual Machine. (CVE-2007-2788,
CVE-2007-2789, CVE-2007-3004)

A denial of service flaw was discovered in the Java Applet Viewer. An
untrusted Java applet could cause the Java Virtual Machine to become
unresponsive. Please note that the BEA WebLogic JRockit 1.5.0_11 does not
ship with a browser plug-in and therefore this issue could only be
triggered by a user running the "appletviewer" application. (CVE-2007-3005)

A cross site scripting (XSS) flaw was found in the Javadoc tool. An
attacker could inject arbitrary content into a Javadoc generated HTML
documentation page, possibly tricking a user or stealing sensitive
information. (CVE-2007-3503)

A denial of service flaw was found in the way the JSSE component processed
SSL/TLS handshake requests. A remote attacker able to connect to a JSSE
enabled service could send a specially crafted handshake which would cause
the Java Runtime Environment to stop responding to future requests. 
(CVE-2007-3698)

A flaw was found in the way the Java Runtime Environment processes font
data. An applet viewed via the 'appletviewer' application could elevate
its privileges, allowing the applet to perform actions with the same
permissions as the user running the "appletviewer" application. It may also
be possible to crash a server application which processes untrusted font
information from a third party. (CVE-2007-4381)

All users of java-bea-1.5.0 should upgrade to these updated packages, which
contain the BEA WebLogic JRockit 1.5.0_11 release that resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-16" />
        <updated date="2007-11-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0243.html">CVE-2007-0243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2788.html">CVE-2007-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2789.html">CVE-2007-2789</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3503.html">CVE-2007-3503</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3698.html">CVE-2007-3698</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4381.html">CVE-2007-4381</cve>
                <bugzilla href="http://bugzilla.redhat.com/242595" id="242595">CVE-2007-3004 Integer overflow in IBM JDK's ICC profile parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246765" id="246765">CVE-2007-3503 HTML files generated with Javadoc are vulnerable to a XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249539" id="249539">CVE-2007-3698 Java Secure Socket Extension Does Not Correctly Process SSL/TLS Handshake Requests Resulting in a Denial of Service (DoS) Condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250725" id="250725">CVE-2007-2788 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250729" id="250729">CVE-2007-2789  BMP image parser vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250733" id="250733">CVE-2007-3005 Unspecified vulnerability in Sun JRE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253488" id="253488">CVE-2007-4381 java: Vulnerability in the font parsing code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/325941" id="325941">CVE-2007-0243 java-jre: GIF buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956002" comment="java-1.5.0-bea is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956003" comment="java-1.5.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956012" comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956013" comment="java-1.5.0-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956010" comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956011" comment="java-1.5.0-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956004" comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956005" comment="java-1.5.0-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956006" comment="java-1.5.0-bea-src is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956007" comment="java-1.5.0-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070956008" comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070956009" comment="java-1.5.0-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070957" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0957: opal security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0957-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0957.html" />
          <reference source="CVE" ref_id="CVE-2007-4924" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4924.html" />
    
    <description>Open Phone Abstraction Library (opal) is implementation of various
telephony and video communication protocols for use over packet based 
networks.

In Red Hat Enterprise Linux 5, the Ekiga application uses opal.

A flaw was discovered in the way opal handled certain Session Initiation 
Protocol (SIP) packets.  An attacker could use this flaw to crash an 
application, such as Ekiga, which is linked with opal. (CVE-2007-4924)

Users should upgrade to these updated opal packages which contain a 
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-08" />
        <updated date="2007-10-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4924.html">CVE-2007-4924</cve>
                <bugzilla href="http://bugzilla.redhat.com/296371" id="296371">CVE-2007-4924 ekiga remote crash caused by insufficient input validation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070957002" comment="opal is earlier than 0:2.2.2-1.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070957003" comment="opal is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070957004" comment="opal-devel is earlier than 0:2.2.2-1.1.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070957005" comment="opal-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070960" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0960: hplip security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0960-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0960.html" />
          <reference source="CVE" ref_id="CVE-2007-5208" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5208.html" />
    
    <description>The hplip (Hewlett-Packard Linux Imaging and Printing Project) package
provides drivers for HP printers and multi-function peripherals.

Kees Cook discovered a flaw in the way the hplip hpssd daemon handled user
input. A local attacker could send a specially crafted request to the hpssd
daemon, possibly allowing them to run arbitrary commands as the root user.
(CVE-2007-5208). On Red Hat Enterprise Linux 5, the SELinux targeted
policy for hpssd which is enabled by default, blocks the ability to exploit
this issue to run arbitrary code.

Users of hplip are advised to upgrade to this updated package, which
contains backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-10-11" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5208.html">CVE-2007-5208</cve>
                <bugzilla href="http://bugzilla.redhat.com/319921" id="319921">CVE-2007-5208 hplip arbitrary command execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070960002" comment="hplip is earlier than 0:1.6.7-4.1.el5_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070960003" comment="hplip is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070960006" comment="libsane-hpaio is earlier than 0:1.6.7-4.1.el5_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070960007" comment="libsane-hpaio is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070960004" comment="hpijs is earlier than 0:1.6.7-4.1.el5_0.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070960005" comment="hpijs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070961" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0961: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0961-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0961.html" />
          <reference source="CVE" ref_id="CVE-2006-6303" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6303.html" />
          <reference source="CVE" ref_id="CVE-2007-5162" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5162.html" />
          <reference source="CVE" ref_id="CVE-2007-5770" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5770.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

A flaw was discovered in the way Ruby's CGI module handles certain HTTP
requests. If a remote attacker sends a specially crafted request, it is
possible to cause the ruby CGI script to enter an infinite loop, possibly
causing a denial of service. (CVE-2006-6303)

An SSL certificate validation flaw was discovered in several Ruby Net
modules. The libraries were not checking the requested host name against
the common name (CN) in the SSL server certificate, possibly allowing a man
in the middle attack. (CVE-2007-5162, CVE-2007-5770)

Users of Ruby should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-13" />
        <updated date="2007-11-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6303.html">CVE-2006-6303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5162.html">CVE-2007-5162</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5770.html">CVE-2007-5770</cve>
                <bugzilla href="http://bugzilla.redhat.com/218287" id="218287">CVE-2006-6303 ruby's cgi.rb vulnerable infinite loop DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/313691" id="313691">CVE-2007-5162 ruby Net:HTTP insufficient verification of SSL certificate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/362081" id="362081">CVE-2007-5770 ruby insufficient verification of SSL certificate in various net::* modules</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961012" comment="ruby-docs is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961013" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961008" comment="irb is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961009" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961004" comment="ruby-mode is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961005" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961014" comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961015" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961010" comment="ruby-libs is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961011" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961002" comment="ruby is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961003" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070961006" comment="ruby-devel is earlier than 0:1.8.1-7.EL4.8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070961007" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070963" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0963: java-1.5.0-sun security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0963-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0963.html" />
          <reference source="CVE" ref_id="CVE-2007-5232" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5232.html" />
          <reference source="CVE" ref_id="CVE-2007-5238" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5238.html" />
          <reference source="CVE" ref_id="CVE-2007-5239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5239.html" />
          <reference source="CVE" ref_id="CVE-2007-5240" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5240.html" />
          <reference source="CVE" ref_id="CVE-2007-5273" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5273.html" />
          <reference source="CVE" ref_id="CVE-2007-5274" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5274.html" />
          <reference source="CVE" ref_id="CVE-2007-5689" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5689.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools
that users need to run applets and applications written using the Java
programming language.

A flaw in the applet caching mechanism of the Java Runtime Environment
(JRE) did not correctly process the creation of network connections. A
remote attacker could use this flaw to create connections to
services on machines other than the one that the applet was downloaded
from. (CVE-2007-5232) 

Multiple vulnerabilities existed in Java Web Start allowing an untrusted
application to determine the location of the Java Web Start cache.
(CVE-2007-5238)

Untrusted Java Web Start Applications or Java Applets were able to drag and
drop a file to a Desktop Application. A user-assisted remote attacker could
use this flaw to move or copy arbitrary files. (CVE-2007-5239)

The Java Runtime Environment (JRE) allowed untrusted Java Applets or
applications to display oversized Windows. This could be used by remote
attackers to hide security warning banners. (CVE-2007-5240)

Unsigned Java Applets communicating via a HTTP proxy could allow a remote
attacker to violate the Java security model. A cached, malicious Applet 
could create network connections to services on other machines. 
(CVE-2007-5273)

Unsigned Applets loaded with Mozilla Firefox or Opera browsers allowed
remote attackers to violate the Java security model. A cached, malicious 
Applet could create network connections to services on other machines. 
(CVE-2007-5274)

In Red Hat Enterprise Linux a Java Web Start application requesting
elevated permissions is only started automatically when signed with a
trusted code signing certificate and otherwise requires user confirmation
to access privileged resources. 

All users of java-sun-1.5.0 should upgrade to these packages, which contain
Sun Java 1.5.0 Update 13 that corrects these issues.

Please note that during our quality testing we discovered that the Java
browser plug-in may not function perfectly when visiting some sites that
make use of multiple applets on a single HTML page.  We have verified that
this issue is not due to our packaging and affects Sun Java 1.5.0 Update 13.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-12" />
        <updated date="2007-10-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5232.html">CVE-2007-5232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5238.html">CVE-2007-5238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5239.html">CVE-2007-5239</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5240.html">CVE-2007-5240</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5273.html">CVE-2007-5273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5274.html">CVE-2007-5274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5689.html">CVE-2007-5689</cve>
                <bugzilla href="http://bugzilla.redhat.com/321951" id="321951">CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321961" id="321961">CVE-2007-5238  Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321981" id="321981">CVE-2007-5239 Untrusted Application or Applet May Move or Copy Arbitrary Files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321991" id="321991">CVE-2007-5240 Applets or Applications are allowed to display an oversized window</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324351" id="324351">CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324361" id="324361">CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963002" comment="java-1.5.0-sun is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963010" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963011" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963008" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963009" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963004" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963005" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070963006" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070963007" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070964" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0964: openssl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0964-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0964.html" />
          <reference source="CVE" ref_id="CVE-2007-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3108.html" />
          <reference source="CVE" ref_id="CVE-2007-4995" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4995.html" />
          <reference source="CVE" ref_id="CVE-2007-5135" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5135.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library. Datagram TLS (DTLS) is a protocol
based on TLS that is capable of securing datagram transport (UDP for
instance). 

The OpenSSL security team discovered a flaw in DTLS support.  An attacker
could create a malicious client or server that could trigger a heap
overflow. This is possibly exploitable to run arbitrary code, but it has
not been verified  (CVE-2007-4995). Note that this flaw only affects
applications making use of DTLS. Red Hat does not ship any DTLS client or
server applications in Red Hat Enterprise Linux.

A flaw was found in the SSL_get_shared_ciphers() utility function. An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer with a single byte (CVE-2007-5135). Few
applications make use of this vulnerable function and generally it is used
only when applications are compiled for debugging.

A number of possible side-channel attacks were discovered affecting
OpenSSL. A local attacker could possibly obtain RSA private keys being
used on a system. In practice these attacks would be difficult to perform
outside of a lab environment. This update contains backported patches
designed to mitigate these issues.  (CVE-2007-3108).

Users of OpenSSL should upgrade to these updated packages, which contain
backported patches to resolve these issues.  

Please note that the fix for the DTLS flaw involved an overhaul of the DTLS
handshake processing which may introduce incompatibilities if a new client
is used with an older server.

After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-12" />
        <updated date="2007-10-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3108.html">CVE-2007-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4995.html">CVE-2007-4995</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5135.html">CVE-2007-5135</cve>
                <bugzilla href="http://bugzilla.redhat.com/245732" id="245732">CVE-2007-3108 openssl: RSA side-channel attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/309801" id="309801">CVE-2007-5135 openssl SSL_get_shared_ciphers() off-by-one</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321191" id="321191">CVE-2007-4995 openssl dtls out of order vulnerabilitiy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070964002" comment="openssl is earlier than 0:0.9.8b-8.3.el5_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070964003" comment="openssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070964006" comment="openssl-perl is earlier than 0:0.9.8b-8.3.el5_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070964007" comment="openssl-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070964004" comment="openssl-devel is earlier than 0:0.9.8b-8.3.el5_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070964005" comment="openssl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070965" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0965: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0965-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0965.html" />
          <reference source="CVE" ref_id="CVE-2007-5162" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5162.html" />
          <reference source="CVE" ref_id="CVE-2007-5770" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5770.html" />
    
    <description>Ruby is an interpreted scripting language for object-oriented programming.

An SSL certificate validation flaw was discovered in several Ruby Net
modules. The libraries were not checking the requested host name against
the common name (CN) in the SSL server certificate, possibly allowing a man
in the middle attack. (CVE-2007-5162, CVE-2007-5770)

Users of Ruby should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-13" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5162.html">CVE-2007-5162</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5770.html">CVE-2007-5770</cve>
                <bugzilla href="http://bugzilla.redhat.com/313691" id="313691">CVE-2007-5162 ruby Net:HTTP insufficient verification of SSL certificate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/362081" id="362081">CVE-2007-5770 ruby insufficient verification of SSL certificate in various net::* modules</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965016" comment="ruby-docs is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965017" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965014" comment="ruby-ri is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965015" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965004" comment="ruby-mode is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965005" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965018" comment="ruby-libs is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965019" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965008" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965009" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965010" comment="ruby-irb is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965011" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965006" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965007" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965002" comment="ruby is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070965012" comment="ruby-devel is earlier than 0:1.8.5-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070965013" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070966" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0966: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0966-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0966.html" />
          <reference source="CVE" ref_id="CVE-2007-5116" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5116.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

A flaw was found in Perl's regular expression engine. Specially crafted
input to a regular expression can cause Perl to improperly allocate memory,
possibly resulting in arbitrary code running with the permissions of the
user running Perl. (CVE-2007-5116)

Users of Perl are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-05" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5116.html">CVE-2007-5116</cve>
                <bugzilla href="http://bugzilla.redhat.com/323571" id="323571">CVE-2007-5116 perl regular expression UTF parsing errors</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966004" comment="perl-suidperl is earlier than 4:5.8.8-10.el5_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966005" comment="perl-suidperl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966002" comment="perl is earlier than 4:5.8.8-10.el5_0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966003" comment="perl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966015" comment="perl-CGI is earlier than 2:2.89-97.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966016" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966013" comment="perl-DB_File is earlier than 2:1.806-97.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966014" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966009" comment="perl-suidperl is earlier than 2:5.8.0-97.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966010" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966011" comment="perl-CPAN is earlier than 2:1.61-97.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966012" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966007" comment="perl is earlier than 2:5.8.0-97.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966008" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966019" comment="perl-suidperl is earlier than 3:5.8.5-36.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966010" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070966018" comment="perl is earlier than 3:5.8.5-36.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070966008" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070967" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0967: pcre security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0967-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0967.html" />
          <reference source="CVE" ref_id="CVE-2007-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1659.html" />
          <reference source="CVE" ref_id="CVE-2007-1660" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1660.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Multiple flaws were found in the way pcre handles certain malformed regular
expressions. If an application linked against pcre, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2007-1659, CVE-2007-1660)

Users of pcre are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-05" />
        <updated date="2007-11-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1659.html">CVE-2007-1659</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1660.html">CVE-2007-1660</cve>
                <bugzilla href="http://bugzilla.redhat.com/315871" id="315871">CVE-2007-1659 pcre regular expression flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/315881" id="315881">CVE-2007-1660 pcre regular expression flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070967004" comment="pcre-devel is earlier than 0:6.6-2.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967005" comment="pcre-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070967002" comment="pcre is earlier than 0:6.6-2.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967003" comment="pcre is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070968" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0968: pcre security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0968-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0968.html" />
          <reference source="CVE" ref_id="CVE-2007-1660" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1660.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Multiple flaws were found in the way pcre handles certain malformed regular
expressions. If an application linked against pcre, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2007-1660)

Users of pcre are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly
disclosing these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-05" />
        <updated date="2007-11-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1660.html">CVE-2007-1660</cve>
                <bugzilla href="http://bugzilla.redhat.com/315881" id="315881">CVE-2007-1660 pcre regular expression flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070968004" comment="pcre-devel is earlier than 0:4.5-4.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070968002" comment="pcre is earlier than 0:4.5-4.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070969" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0969: util-linux security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0969-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0969.html" />
          <reference source="CVE" ref_id="CVE-2007-5191" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5191.html" />
    
    <description>The util-linux package contains a large variety of low-level system
utilities that are necessary for a Linux system to function. 

A flaw was discovered in the way that the mount and umount utilities
used the setuid and setgid functions, which could lead to privileges being
dropped improperly.  A local user could use this flaw to run mount helper
applications such as, mount.nfs, with additional privileges (CVE-2007-5191).

Users are advised to update to these erratum packages which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5191.html">CVE-2007-5191</cve>
                <bugzilla href="http://bugzilla.redhat.com/320041" id="320041">CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070969002" comment="util-linux is earlier than 0:2.13-0.45.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070969003" comment="util-linux is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070969005" comment="util-linux is earlier than 0:2.11y-31.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070235003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070969009" comment="mount is earlier than 0:2.11y-31.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070969010" comment="mount is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070969007" comment="losetup is earlier than 0:2.11y-31.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070969008" comment="losetup is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070969012" comment="util-linux is earlier than 0:2.12a-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070235003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070975" version="504" class="patch">
      <metadata>
        <title>RHSA-2007:0975: flac security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0975-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0975.html" />
          <reference source="CVE" ref_id="CVE-2007-4619" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4619.html" />
          <reference source="CVE" ref_id="CVE-2007-6277" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6277.html" />
    
    <description>FLAC is a Free Lossless Audio Codec.  The flac package consists of a FLAC
encoder and decoder in library form, a program to encode and decode FLAC
files, a metadata editor for FLAC files and input plugins for various music
players.

A security flaw was found in the way flac processed audio data. An
attacker could create a carefully crafted FLAC audio file in such a way that
it could cause an application linked with flac libraries to crash or execute
arbitrary code when it was opened. (CVE-2007-4619)

Users of flac are advised to upgrade to this updated package, which
contains a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-10-22" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4619.html">CVE-2007-4619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6277.html">CVE-2007-6277</cve>
                <bugzilla href="http://bugzilla.redhat.com/331991" id="331991">CVE-2007-4619 FLAC Integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070975004" comment="flac-devel is earlier than 0:1.1.2-28.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070975005" comment="flac-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070975002" comment="flac is earlier than 0:1.1.2-28.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070975003" comment="flac is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070975011" comment="flac-devel is earlier than 0:1.1.0-7.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070975012" comment="flac-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070975007" comment="flac is earlier than 0:1.1.0-7.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070975008" comment="flac is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070975009" comment="xmms-flac is earlier than 0:1.1.0-7.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070975010" comment="xmms-flac is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070979" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0979: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0979-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0979.html" />
          <reference source="CVE" ref_id="CVE-2007-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1095.html" />
          <reference source="CVE" ref_id="CVE-2007-2292" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2292.html" />
          <reference source="CVE" ref_id="CVE-2007-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3511.html" />
          <reference source="CVE" ref_id="CVE-2007-3844" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3844.html" />
          <reference source="CVE" ref_id="CVE-2007-5334" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5334.html" />
          <reference source="CVE" ref_id="CVE-2007-5337" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5337.html" />
          <reference source="CVE" ref_id="CVE-2007-5338" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5338.html" />
          <reference source="CVE" ref_id="CVE-2007-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5339.html" />
          <reference source="CVE" ref_id="CVE-2007-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5340.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way in which Firefox processed certain
malformed web content. A web page containing malicious content could cause
Firefox to crash or potentially execute arbitrary code as the user running
Firefox. (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which Firefox displayed malformed
web content. A web page containing specially-crafted content could
potentially trick a user into surrendering sensitive information.
(CVE-2007-1095, CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)

A flaw was found in the Firefox sftp protocol handler. A malicious web page
could access data from a remote sftp site, possibly stealing sensitive user
data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which Firefox generates a
digest authentication request. If a user opened a specially-crafted URL, it
was possible to perform cross-site scripting attacks, web cache poisoning,
or other, similar exploits. (CVE-2007-2292)

All users of Firefox are advised to upgrade to these updated packages,
which contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-10-19" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1095.html">CVE-2007-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2292.html">CVE-2007-2292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3511.html">CVE-2007-3511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3844.html">CVE-2007-3844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5334.html">CVE-2007-5334</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5337.html">CVE-2007-5337</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5338.html">CVE-2007-5338</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5339.html">CVE-2007-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5340.html">CVE-2007-5340</cve>
                <bugzilla href="http://bugzilla.redhat.com/246248" id="246248">firefox crashes when searching for word "do"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/333991" id="333991">Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070979004" comment="firefox-devel is earlier than 0:1.5.0.12-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097011" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070979002" comment="firefox is earlier than 0:1.5.0.12-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070979007" comment="firefox is earlier than 0:1.5.0.12-0.7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070980" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0980: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0980-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0980.html" />
          <reference source="CVE" ref_id="CVE-2007-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1095.html" />
          <reference source="CVE" ref_id="CVE-2007-2292" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2292.html" />
          <reference source="CVE" ref_id="CVE-2007-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3511.html" />
          <reference source="CVE" ref_id="CVE-2007-3844" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3844.html" />
          <reference source="CVE" ref_id="CVE-2007-5334" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5334.html" />
          <reference source="CVE" ref_id="CVE-2007-5337" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5337.html" />
          <reference source="CVE" ref_id="CVE-2007-5338" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5338.html" />
          <reference source="CVE" ref_id="CVE-2007-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5339.html" />
          <reference source="CVE" ref_id="CVE-2007-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5340.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way in which SeaMonkey processed certain
malformed web content. A web page containing malicious content could cause
SeaMonkey to crash or potentially execute arbitrary code as the user
running SeaMonkey. (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which SeaMonkey displayed malformed
web content. A web page containing specially-crafted content could
potentially trick a user into surrendering sensitive information. 
(CVE-2007-1095, CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)

A flaw was found in the SeaMonkey sftp protocol handler. A malicious web
page could access data from a remote sftp site, possibly stealing sensitive
user data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which SeaMonkey generates
a digest authentication request. If a user opened a specially-crafted URL,
it was possible to perform cross-site scripting attacks, web cache
poisoning, or other, similar exploits. (CVE-2007-2292)

Users of SeaMonkey are advised to upgrade to these erratum packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-19" />
        <updated date="2007-10-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1095.html">CVE-2007-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2292.html">CVE-2007-2292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3511.html">CVE-2007-3511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3844.html">CVE-2007-3844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5334.html">CVE-2007-5334</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5337.html">CVE-2007-5337</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5338.html">CVE-2007-5338</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5339.html">CVE-2007-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5340.html">CVE-2007-5340</cve>
                <bugzilla href="http://bugzilla.redhat.com/333991" id="333991">Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980014" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980006" comment="seamonkey-mail is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980002" comment="seamonkey is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980018" comment="seamonkey-devel is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980020" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980012" comment="seamonkey-nss is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980010" comment="seamonkey-chat is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.5.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980029" comment="seamonkey-nspr is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980026" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980024" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980030" comment="seamonkey-mail is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980023" comment="seamonkey is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980028" comment="seamonkey-devel is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980032" comment="seamonkey-chat is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980031" comment="seamonkey-nss is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980027" comment="seamonkey-nss-devel is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070980025" comment="seamonkey-js-debugger is earlier than 0:1.0.9-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070981" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0981: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0981-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0981.html" />
          <reference source="CVE" ref_id="CVE-2007-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1095.html" />
          <reference source="CVE" ref_id="CVE-2007-2292" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2292.html" />
          <reference source="CVE" ref_id="CVE-2007-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3511.html" />
          <reference source="CVE" ref_id="CVE-2007-3844" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3844.html" />
          <reference source="CVE" ref_id="CVE-2007-5334" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5334.html" />
          <reference source="CVE" ref_id="CVE-2007-5337" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5337.html" />
          <reference source="CVE" ref_id="CVE-2007-5338" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5338.html" />
          <reference source="CVE" ref_id="CVE-2007-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5339.html" />
          <reference source="CVE" ref_id="CVE-2007-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5340.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the way in which Thunderbird processed certain
malformed HTML mail content. An HTML mail message containing malicious
content could cause Thunderbird to crash or potentially execute arbitrary
code as the user running Thunderbird. JavaScript support is disabled by
default in Thunderbird; these issues are not exploitable unless the user
has enabled JavaScript.  (CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)

Several flaws were found in the way in which Thunderbird displayed
malformed HTML mail content. An HTML mail message containing
specially-crafted content could potentially trick a user into surrendering
sensitive information.  (CVE-2007-1095, CVE-2007-3844, CVE-2007-3511,
CVE-2007-5334)

A flaw was found in the Thunderbird sftp protocol handler. A malicious HTML
mail message could access data from a remote sftp site, possibly stealing
sensitive user data. (CVE-2007-5337)

A request-splitting flaw was found in the way in which Thunderbird
generates a digest authentication request. If a user opened a
specially-crafted URL, it was possible to perform cross-site scripting
attacks, web cache poisoning, or other, similar exploits. (CVE-2007-2292)

Users of Thunderbird are advised to upgrade to these erratum packages,
which contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-10-19" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1095.html">CVE-2007-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2292.html">CVE-2007-2292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3511.html">CVE-2007-3511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3844.html">CVE-2007-3844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5334.html">CVE-2007-5334</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5337.html">CVE-2007-5337</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5338.html">CVE-2007-5338</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5339.html">CVE-2007-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5340.html">CVE-2007-5340</cve>
                <bugzilla href="http://bugzilla.redhat.com/333991" id="333991">Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070981002" comment="thunderbird is earlier than 0:1.5.0.12-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070981005" comment="thunderbird is earlier than 0:1.5.0.12-0.5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070992" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:0992: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0992-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0992.html" />
          <reference source="CVE" ref_id="CVE-2007-5269" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5269.html" />
    
    <description>The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

Several flaws were discovered in the way libpng handled various PNG image
chunks.  An attacker could create a carefully crafted PNG image file in
such a way that it could cause an application linked with libpng to crash
when the file was manipulated. (CVE-2007-5269)

Users should update to these updated packages which contain a backported
patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-23" />
        <updated date="2007-10-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5269.html">CVE-2007-5269</cve>
                <bugzilla href="http://bugzilla.redhat.com/324771" id="324771">CVE-2007-5269 libpng DoS via multiple out-of-bounds reads</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992002" comment="libpng is earlier than 2:1.2.10-7.1.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356003" comment="libpng is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992004" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356005" comment="libpng-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992007" comment="libpng is earlier than 2:1.2.2-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992009" comment="libpng-devel is earlier than 2:1.2.2-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992013" comment="libpng10-devel is earlier than 0:1.0.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992011" comment="libpng10 is earlier than 0:1.0.13-18" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992016" comment="libpng is earlier than 2:1.2.7-3.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992017" comment="libpng-devel is earlier than 2:1.2.7-3.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992019" comment="libpng10-devel is earlier than 0:1.0.16-3.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070992018" comment="libpng10 is earlier than 0:1.0.16-3.el4_5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070356012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070993" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:0993: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:0993-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0993.html" />
          <reference source="CVE" ref_id="CVE-2007-4571" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4571.html" />
          <reference source="CVE" ref_id="CVE-2007-4997" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4997.html" />
          <reference source="CVE" ref_id="CVE-2007-5494" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5494.html" />
    
    <description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the following security issues:

A memory leak was found in the Red Hat Content Accelerator kernel patch.  A
local user could use this flaw to cause a denial of service (memory
exhaustion). (CVE-2007-5494, Important)

A flaw was found in the handling of IEEE 802.11 frames affecting several
wireless LAN modules.  In certain circumstances, a remote attacker could
trigger this flaw by sending a malicious packet over a wireless network and
cause a denial of service (kernel crash). (CVE-2007-4997, Important). 

A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local
user who had the ability to read the /proc/driver/snd-page-alloc file could
see portions of kernel memory. (CVE-2007-4571, Moderate). 

In addition to the security issues described above, several bug fixes
preventing possible memory corruption, system crashes, SCSI I/O fails,
networking drivers performance regression and journaling block device layer
issue were also included.

Red Hat Enterprise Linux 5 users are advised to upgrade to these packages,
which contain backported patches to resolve these issues.

Red Hat would like to credit Vasily Averin, Chris Evans, and Neil Kettle 
for reporting the security issues corrected by this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-29" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4571.html">CVE-2007-4571</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4997.html">CVE-2007-4997</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5494.html">CVE-2007-5494</cve>
                <bugzilla href="http://bugzilla.redhat.com/288961" id="288961">CVE-2007-4571 ALSA memory disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/305011" id="305011">[RHEL 5.1.z]: Tick divider bugs on x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/315051" id="315051">CVE-2007-5494 open(O_ATOMICLOOKUP) leaks dentry</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345141" id="345141">[PATCH] jbd: wait for already submitted t_sync_datalist buffer to complete (Possibility of in-place data destruction)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345151" id="345151">LSPP: audit rule causes kernel 'out of memory' condition and auditd failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345161" id="345161">[EL5][BUG] Unexpected SIGILL on NFS/Montecito(ia64)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345171" id="345171">task->mm or slab corruption with CIFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/346341" id="346341">CVE-2007-4997 kernel ieee80211 off-by-two integer underflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381001" id="381001">LSPP: audit enable not picking up all processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381021" id="381021">[Broadcom 5.1.z bug] Performance regression on 5705 TG3 NICs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381101" id="381101">LTC35628-kexec/kdump kernel hung on Power5+ and Power6 based systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381121" id="381121">LTC38135-vSCSI client reports 'Device sdX not ready' after deactive/active device on vSCSI server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381131" id="381131">forcedeth driver mishandles MSI interrupts under high load</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993004" comment="kernel-headers is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993002" comment="kernel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993024" comment="kernel-doc is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099021" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993020" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099017" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993008" comment="kernel-devel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099011" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993006" comment="kernel-debug is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070993007" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993016" comment="kernel-kdump is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099015" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993010" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099009" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993012" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070993013" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993022" comment="kernel-PAE is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099019" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993018" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099013" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070993014" comment="kernel-xen is earlier than 0:2.6.18-53.1.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070099007" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071003" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1003: openssl security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1003-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1003.html" />
          <reference source="CVE" ref_id="CVE-2007-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3108.html" />
          <reference source="CVE" ref_id="CVE-2007-5135" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5135.html" />
    
    <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, and is also a
full-strength general-purpose cryptography library.

A flaw was found in the SSL_get_shared_ciphers() utility function. An
attacker could send a list of ciphers to an application that used this
function and overrun a buffer by a single byte (CVE-2007-5135). Few
applications make use of this vulnerable function and generally it is used
only when applications are compiled for debugging. 

A number of possible side-channel attacks were discovered affecting
OpenSSL. A local attacker could possibly obtain RSA private keys being used
on a system. In practice these attacks would be difficult to perform
outside of a lab environment. This update contains backported patches to
mitigate these issues. (CVE-2007-3108)

As well, these updated packages fix the following bugs:

* multithreaded applications could cause a segmentation fault or deadlock
when calling the random number generator initialization (RAND_poll) in the
OpenSSL library, for a large number of threads simultaneously.

* in certain circumstances, if an application using the OpenSSL library
reused the SSL session cache for multiple purposes (with various parameters
of the SSL protocol), the session parameters could be mismatched.

* a segmentation fault could occur when a corrupted pkcs12 file was being
loaded using the "openssl pkcs12 -in [pkcs12-file]" command, where
[pkcs12-file] is the pkcs12 file.

Users of OpenSSL should upgrade to these updated packages, which contain
backported patches to resolve these issues.

Note: After installing this update, users are advised to either restart all
services that use OpenSSL or restart their system.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3108.html">CVE-2007-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5135.html">CVE-2007-5135</cve>
                <bugzilla href="http://bugzilla.redhat.com/236164" id="236164">openssl RAND_poll segfault when fd >= FD_SETSIZE (affects apache2 startup with many SSL vhosts)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245083" id="245083">openssl crashes on pkcs12 file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245732" id="245732">CVE-2007-3108 openssl: RSA side-channel attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250573" id="250573">CVE-NONE openssl branch prediction attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/309801" id="309801">CVE-2007-5135 openssl SSL_get_shared_ciphers() off-by-one</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071003002" comment="openssl is earlier than 0:0.9.7a-43.17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813003" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071003006" comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813007" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071003004" comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070813005" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071013" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1013: samba security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1013.html" />
          <reference source="CVE" ref_id="CVE-2007-4572" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4572.html" />
          <reference source="CVE" ref_id="CVE-2007-5398" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5398.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap-based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

Red Hat would like to thank Alin Rad Pop of Secunia Research, and the Samba
developers for responsibly disclosing these issues.

Users of Samba are advised to ugprade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4572.html">CVE-2007-4572</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5398.html">CVE-2007-5398</cve>
                <bugzilla href="http://bugzilla.redhat.com/294631" id="294631">CVE-2007-4572 samba buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/358831" id="358831">CVE-2007-5398 Samba "reply_netbios_packet()" Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071013006" comment="samba-client is earlier than 0:3.0.9-1.3E.14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071013008" comment="samba-common is earlier than 0:3.0.9-1.3E.14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071013002" comment="samba is earlier than 0:3.0.9-1.3E.14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071013004" comment="samba-swat is earlier than 0:3.0.9-1.3E.14.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071016" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1016: samba security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1016-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1016.html" />
          <reference source="CVE" ref_id="CVE-2007-4572" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4572.html" />
          <reference source="CVE" ref_id="CVE-2007-4138" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4138.html" />
          <reference source="CVE" ref_id="CVE-2007-5398" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5398.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap-based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

A flaw was found in the way Samba assigned group IDs under certain
conditions. If the "winbind nss info" parameter in smb.conf is set to
either "sfu" or "rfc2307", Samba users are incorrectly assigned the group
ID of 0. (CVE-2007-4138)

Red Hat would like to thank Alin Rad Pop of Secunia Research, Rick King,
and the Samba developers for responsibly disclosing these issues.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4572.html">CVE-2007-4572</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4138.html">CVE-2007-4138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5398.html">CVE-2007-5398</cve>
                <bugzilla href="http://bugzilla.redhat.com/286271" id="286271">CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/294631" id="294631">CVE-2007-4572 samba buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/358831" id="358831">CVE-2007-5398 Samba "reply_netbios_packet()" Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071016008" comment="samba-client is earlier than 0:3.0.25b-1.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071016004" comment="samba-common is earlier than 0:3.0.25b-1.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071016002" comment="samba is earlier than 0:3.0.25b-1.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071016006" comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071017" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1017: samba security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1017-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1017.html" />
          <reference source="CVE" ref_id="CVE-2007-4572" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4572.html" />
          <reference source="CVE" ref_id="CVE-2007-4138" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4138.html" />
          <reference source="CVE" ref_id="CVE-2007-5398" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5398.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A buffer overflow flaw was found in the way Samba creates NetBIOS replies.
If a Samba server is configured to run as a WINS server, a remote
unauthenticated user could cause the Samba server to crash or execute
arbitrary code. (CVE-2007-5398)

A heap based buffer overflow flaw was found in the way Samba authenticates
users. A remote unauthenticated user could trigger this flaw to cause the
Samba server to crash. Careful analysis of this flaw has determined that
arbitrary code execution is not possible, and under most circumstances will
not result in a crash of the Samba server. (CVE-2007-4572)

A flaw was found in the way Samba assigned group IDs under certain
conditions. If the "winbind nss info" parameter in smb.conf is set to
either "sfu" or "rfc2307", Samba users are incorrectly assigned the group
ID of 0. (CVE-2007-4138)

Red Hat would like to thank Alin Rad Pop of Secunia Research, Rick King,
and the Samba developers for responsibly disclosing these issues.

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4572.html">CVE-2007-4572</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4138.html">CVE-2007-4138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5398.html">CVE-2007-5398</cve>
                <bugzilla href="http://bugzilla.redhat.com/286271" id="286271">CVE-2007-4138 samba incorrect primary group assignment for domain users using the rfc2307 or sfu winbind nss info plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/294631" id="294631">CVE-2007-4572 samba buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/358831" id="358831">CVE-2007-5398 Samba "reply_netbios_packet()" Buffer Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071017004" comment="samba-client is earlier than 0:3.0.25b-1.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071017006" comment="samba-common is earlier than 0:3.0.25b-1.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061005" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071017002" comment="samba is earlier than 0:3.0.25b-1.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071017008" comment="samba-swat is earlier than 0:3.0.25b-1.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061007" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071020" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1020: cups security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1020-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1020.html" />
          <reference source="CVE" ref_id="CVE-2007-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4351.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A flaw was found in the way CUPS handles certain Internet Printing Protocol
(IPP) tags. A remote attacker who is able to connect to the IPP TCP port
could send a malicious request causing the CUPS daemon to crash, or
potentially execute arbitrary code. Please note that the default CUPS
configuration does not allow remote hosts to connect to the IPP TCP port.
(CVE-2007-4351)

Red Hat would like to thank Alin Rad Pop for reporting this issue.

All CUPS users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.

In addition, the following bugs were fixed:

* the CUPS service has been changed to start after sshd, to avoid causing
delays when logging in when the system is booted.

* the logrotate settings have been adjusted so they do not cause CUPS to
reload its configuration. This is to avoid re-printing the current job,
which could occur when it was a long-running job.

* a bug has been fixed in the handling of the If-Modified-Since: HTTP
header.

* in the LSPP configuration, labels for labeled jobs did not line-wrap.
This has been fixed.

* an access check in the LSPP configuration has been made more secure.

* the cups-lpd service no longer ignores the "-odocument-format=..."
option.

* a memory allocation bug has been fixed in cupsd.

* support for UNIX domain sockets authentication without passwords has been
added.

* in the LSPP configuration, a problem that could lead to cupsd crashing
has been fixed.

* the error handling in the initscript has been improved.

* The job-originating-host-name attribute was not correctly set for jobs
submitted via the cups-lpd service. This has been fixed.

* a problem with parsing IPv6 addresses in the configuration file has been
fixed.

* a problem that could lead to cupsd crashing when it failed to open a
"file:" URI has been fixed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-10-31" />
        <updated date="2007-10-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4351.html">CVE-2007-4351</cve>
                <bugzilla href="http://bugzilla.redhat.com/213828" id="213828">Cups starts as S55cups, before sshd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/228107" id="228107">[LSPP] Labels for labeled printing don't linewrap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/229673" id="229673">[LSPP] cups is overriding mls when querying jobs with lpq -al</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230073" id="230073">cups-lpd : server-args has no effect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/230613" id="230613">[LSPP] cups is allowing users to delete other user's job</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231522" id="231522">[LSPP] cupsd crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/237953" id="237953">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240223" id="240223">cups-lpd doesn't set 'job-originating-host-name'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241400" id="241400">IPV6 addresses not accepted in  "Allow From" directives</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250415" id="250415">cupsd crashes when failing to open a file: URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345091" id="345091">CVE-2007-4351 cups boundary error</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071020006" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123005" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071020008" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123009" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071020004" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123007" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071020002" comment="cups is earlier than 1:1.2.4-11.14.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071021" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1021: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1021-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1021.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause CUPS to crash
or potentially execute arbitrary code when printed. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071021004" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123005" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071021006" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123009" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071021008" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123007" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071021002" comment="cups is earlier than 1:1.2.4-11.14.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071022" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1022: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1022-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1022.html" />
          <reference source="CVE" ref_id="CVE-2007-4045" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4045.html" />
          <reference source="CVE" ref_id="CVE-2007-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4351.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause CUPS to crash
or potentially execute arbitrary code when printed.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.
A remote attacker who is able to connect to the IPP TCP port could send a
malicious request causing the CUPS daemon to crash. (CVE-2007-4351)

A flaw was found in the way CUPS handled SSL negotiation. A remote attacker
capable of connecting to the CUPS daemon could cause CUPS to crash.
(CVE-2007-4045)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4045.html">CVE-2007-4045</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4351.html">CVE-2007-4351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/250161" id="250161">CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345091" id="345091">CVE-2007-4351 cups boundary error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071022006" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071022004" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071022002" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071023" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1023: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1023-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1023.html" />
          <reference source="CVE" ref_id="CVE-2007-4045" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4045.html" />
          <reference source="CVE" ref_id="CVE-2007-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4351.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker
could create a malicious PDF file that would cause CUPS to crash or
potentially execute arbitrary code when printed. (CVE-2007-5393)

Alin Rad Pop discovered a flaw in in the way CUPS handles certain IPP tags.
A remote attacker who is able to connect to the IPP TCP port could send a
malicious request causing the CUPS daemon to crash. (CVE-2007-4351)

A flaw was found in the way CUPS handled SSL negotiation. A remote attacker
capable of connecting to the CUPS daemon could cause CUPS to crash.
(CVE-2007-4045)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4045.html">CVE-2007-4045</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4351.html">CVE-2007-4351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/250161" id="250161">CVE-2007-4045 Incomplete fix for CVE-2007-0720 CUPS denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345091" id="345091">CVE-2007-4351 cups boundary error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071023006" comment="cups-devel is earlier than 1:1.1.17-13.3.46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123016" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071023004" comment="cups-libs is earlier than 1:1.1.17-13.3.46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123014" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071023002" comment="cups is earlier than 1:1.1.17-13.3.46" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070123012" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071024" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1024: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1024-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1024.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment. This includes kpdf, a PDF file viewer.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause kpdf to crash,
or potentially execute arbitrary code when opened. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-12" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071024002" comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729008" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071024004" comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729010" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071025" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1025: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1025.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>gpdf is a GNOME-based viewer for Portable Document Format (PDF) files. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause gpdf to crash,
or potentially execute arbitrary code when opened.  
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071025002" comment="gpdf is earlier than 0:2.8.2-7.7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070730003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071026" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1026: poppler security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1026-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1026.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>Poppler is a PDF rendering library, used by applications such as evince. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause an application
linked with poppler to crash, or potentially execute arbitrary code when
opened. (CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071026004" comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732007" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071026002" comment="poppler is earlier than 0:0.5.4-4.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071026006" comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070732005" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071027" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1027: tetex security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1027-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1027.html" />
          <reference source="CVE" ref_id="CVE-2007-4033" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4033.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (dvi) file as output. 

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause TeTeX to crash
or potentially execute arbitrary code when opened. 
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

A flaw was found in the t1lib library, used in the handling of Type 1
fonts. An attacker could create a malicious file that would cause TeTeX to
crash, or potentially execute arbitrary code when opened. (CVE-2007-4033)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-08" />
        <updated date="2007-11-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4033.html">CVE-2007-4033</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/352271" id="352271">CVE-2007-4033 t1lib font filename string overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027014" comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731007" comment="tetex-xdvi is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027002" comment="tetex is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731003" comment="tetex is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027012" comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731013" comment="tetex-fonts is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027010" comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731009" comment="tetex-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027004" comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731005" comment="tetex-latex is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027008" comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731011" comment="tetex-dvips is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027006" comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731015" comment="tetex-afm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027019" comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731026" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027017" comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731018" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027021" comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731030" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027027" comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731020" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027025" comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731024" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027029" comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731022" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071027023" comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731028" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071028" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1028: tetex security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1028-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1028.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>TeTeX is an implementation of TeX. TeX takes a text file and a set of
formatting commands as input, and creates a typesetter-independent DeVice
Independent (dvi) file as output.

Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker
could create a malicious PDF file that would cause TeTeX to crash, or
potentially execute arbitrary code when opened. (CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028012" comment="tetex-xdvi is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731026" comment="tetex-xdvi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028002" comment="tetex is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731018" comment="tetex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028006" comment="tetex-fonts is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731030" comment="tetex-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028014" comment="tetex-doc is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731024" comment="tetex-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028004" comment="tetex-latex is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731020" comment="tetex-latex is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028010" comment="tetex-dvips is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731022" comment="tetex-dvips is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071028008" comment="tetex-afm is earlier than 0:1.0.7-67.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070731028" comment="tetex-afm is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071029" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1029: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1029-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1029.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause Xpdf to crash,
or potentially execute arbitrary code when opened.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071029002" comment="xpdf is earlier than 1:3.00-14.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071030" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1030: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1030-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1030.html" />
          <reference source="CVE" ref_id="CVE-2007-4033" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4033.html" />
          <reference source="CVE" ref_id="CVE-2007-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4352.html" />
          <reference source="CVE" ref_id="CVE-2007-5392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5392.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files.

Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause Xpdf to crash,
or potentially execute arbitrary code when opened.  
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)

A flaw was found in the t1lib library, used in the handling of Type 1
fonts. An attacker could create a malicious file that would cause Xpdf to
crash, or potentially execute arbitrary code when opened. (CVE-2007-4033)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-07" />
        <updated date="2007-11-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4033.html">CVE-2007-4033</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4352.html">CVE-2007-4352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5392.html">CVE-2007-5392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345101" id="345101">CVE-2007-4352 xpdf memory corruption in DCTStream::readProgressiveDataUnit()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345111" id="345111">CVE-2007-5392 xpdf buffer overflow in DCTStream::reset()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/352271" id="352271">CVE-2007-4033 t1lib font filename string overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071030002" comment="xpdf is earlier than 1:2.02-11.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070735003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071037" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1037: openldap security and enhancement update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1037.html" />
          <reference source="CVE" ref_id="CVE-2007-5707" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5707.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP's slapd daemon handled malformed
objectClasses LDAP attributes.  A local or remote attacker could create an
LDAP request which could cause a denial of service by crashing slapd.
(CVE-2007-5707)

In addition, the following feature was added: 
* OpenLDAP client tools now have new option to configure their bind timeout.

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue and provide this security
enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-08" />
        <updated date="2007-11-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5707.html">CVE-2007-5707</cve>
                <bugzilla href="http://bugzilla.redhat.com/359851" id="359851">CVE-2007-5707 openldap slapd DoS via objectClasses attribute</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037008" comment="openldap-devel is earlier than 0:2.3.27-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037009" comment="openldap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037004" comment="openldap-clients is earlier than 0:2.3.27-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037005" comment="openldap-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037012" comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037013" comment="openldap-servers-sql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037010" comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037011" comment="compat-openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037002" comment="openldap is earlier than 0:2.3.27-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037003" comment="openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071037006" comment="openldap-servers is earlier than 0:2.3.27-8.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071037007" comment="openldap-servers is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071038" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1038: openldap security and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1038-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1038.html" />
          <reference source="CVE" ref_id="CVE-2007-5707" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5707.html" />
    
    <description>OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP's slapd daemon handled malformed
objectClasses LDAP attributes.  An authenticated local or remote attacker
could create an LDAP request which could cause a denial of service by
crashing slapd. (CVE-2007-5707)

In addition, the following feature was added:
* OpenLDAP client tools now have new option to configure their bind timeout.

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue and provide this security
enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5707.html">CVE-2007-5707</cve>
                <bugzilla href="http://bugzilla.redhat.com/359851" id="359851">CVE-2007-5707 openldap slapd DoS via objectClasses attribute</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038012" comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310009" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038006" comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310007" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038008" comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310011" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038010" comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310013" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038002" comment="openldap is earlier than 0:2.2.13-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310003" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071038004" comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070310005" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071041" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1041: java-1.5.0-ibm security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1041-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1041.html" />
          <reference source="CVE" ref_id="CVE-2007-5232" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5232.html" />
          <reference source="CVE" ref_id="CVE-2007-5238" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5238.html" />
          <reference source="CVE" ref_id="CVE-2007-5240" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5240.html" />
          <reference source="CVE" ref_id="CVE-2007-5239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5239.html" />
          <reference source="CVE" ref_id="CVE-2007-5273" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5273.html" />
          <reference source="CVE" ref_id="CVE-2007-5274" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5274.html" />
    
    <description>IBM's 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

The applet caching mechanism of the Java Runtime Environment (JRE) did not
correctly process the creation of network connections. A remote attacker
could use this flaw to create connections to services on machines other
than the one that the applet was downloaded from. (CVE-2007-5232)

Multiple vulnerabilities existed in Java Web Start allowing an untrusted
application to determine the location of the Java Web Start cache.
(CVE-2007-5238)

Untrusted Java Web Start Applications or Java Applets were able to drag and
drop a file to a Desktop Application. A user-assisted remote attacker could
use this flaw to move or copy arbitrary files. (CVE-2007-5239)

The Java Runtime Environment allowed untrusted Java Applets or applications
to display oversized Windows. This could be used by remote attackers to
hide security warning banners. (CVE-2007-5240)

Unsigned Java Applets communicating via a HTTP proxy could allow a remote
attacker to violate the Java security model. A cached malicious Applet
could create network connections to services on other machines.
(CVE-2007-5273)

Unsigned Applets loaded with Mozilla Firefox or Opera browsers allowed
remote attackers to violate the Java security model. A cached malicious
Applet could create network connections to services on other machines.
(CVE-2007-5274) 

All users of java-ibm-1.5.0 are advised to upgrade to these updated
packages, that contain IBM's 1.5.0 SR6 Java release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-26" />
        <updated date="2007-11-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5232.html">CVE-2007-5232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5238.html">CVE-2007-5238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5240.html">CVE-2007-5240</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5239.html">CVE-2007-5239</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5273.html">CVE-2007-5273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5274.html">CVE-2007-5274</cve>
                <bugzilla href="http://bugzilla.redhat.com/321951" id="321951">CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321961" id="321961">CVE-2007-5238  Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321981" id="321981">CVE-2007-5239 Untrusted Application or Applet May Move or Copy Arbitrary Files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321991" id="321991">CVE-2007-5240 Applets or Applications are allowed to display an oversized window</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324351" id="324351">CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324361" id="324361">CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041004" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167013" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041006" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071041007" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041014" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167011" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041008" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167009" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041012" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041016" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167015" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071041010" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070167007" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071045" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1045: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1045.html" />
          <reference source="CVE" ref_id="CVE-2007-5846" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5846.html" />
    
    <description>Simple Network Management Protocol (SNMP) is a protocol used for network
management.

A flaw was discovered in the way net-snmp handled certain requests. A
remote attacker who can connect to the snmpd UDP port (161 by default)
could send a malicious packet causing snmpd to crash, resulting in a
denial of service. (CVE-2007-5846)

All users of net-snmp are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-15" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5846.html">CVE-2007-5846</cve>
                <bugzilla href="http://bugzilla.redhat.com/363631" id="363631">CVE-2007-5846 net-snmp remote DoS via udp packet</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045010" comment="net-snmp-utils is earlier than 1:5.3.1-19.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045011" comment="net-snmp-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045008" comment="net-snmp-libs is earlier than 1:5.3.1-19.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045009" comment="net-snmp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045006" comment="net-snmp-perl is earlier than 1:5.3.1-19.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045007" comment="net-snmp-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045004" comment="net-snmp-devel is earlier than 1:5.3.1-19.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045005" comment="net-snmp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045002" comment="net-snmp is earlier than 1:5.3.1-19.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045003" comment="net-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045021" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045022" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045019" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045017" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045018" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045015" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045016" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045013" comment="net-snmp is earlier than 0:5.0.9-2.30E.23" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045025" comment="net-snmp-utils is earlier than 0:5.1.2-11.el4_6.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045022" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045028" comment="net-snmp-libs is earlier than 0:5.1.2-11.el4_6.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045027" comment="net-snmp-perl is earlier than 0:5.1.2-11.el4_6.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045016" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045026" comment="net-snmp-devel is earlier than 0:5.1.2-11.el4_6.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045018" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071045024" comment="net-snmp is earlier than 0:5.1.2-11.el4_6.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071045014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071048" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1048: openoffice.org, hsqldb security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1048-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1048.html" />
          <reference source="CVE" ref_id="CVE-2003-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2003-0845.html" />
          <reference source="CVE" ref_id="CVE-2007-4575" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4575.html" />
    
    <description>OpenOffice.org is an office productivity suite.
HSQLDB is a Java relational database engine used by OpenOffice.org Base.

It was discovered that HSQLDB could allow the execution of arbitrary public
static Java methods. A carefully crafted odb file opened in OpenOffice.org
Base could execute arbitrary commands with the permissions of the user
running OpenOffice.org. (CVE-2007-4575)

It was discovered that HSQLDB did not have a password set on the 'sa' user.
 If HSQLDB has been configured as a service, a remote attacker who could
connect to the HSQLDB port (tcp 9001) could execute arbitrary SQL commands.
(CVE-2003-0845)

Note that in Red Hat Enterprise Linux 5, HSQLDB is not enabled as a service
by default, and needs manual configuration in order to work as a service.

Users of OpenOffice.org or HSQLDB should update to these errata packages
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-05" />
        <updated date="2007-12-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2003-0845.html">CVE-2003-0845</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4575.html">CVE-2007-4575</cve>
                <bugzilla href="http://bugzilla.redhat.com/299801" id="299801">CVE-2007-4575 OpenOffice.org-base allows Denial-of-Service and command injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/409891" id="409891">CVE-2003-0845 JBoss HSQLDB component remote command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048006" comment="hsqldb-javadoc is earlier than 1:1.8.0.4-3jpp.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071048007" comment="hsqldb-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048004" comment="hsqldb-manual is earlier than 1:1.8.0.4-3jpp.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071048005" comment="hsqldb-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048002" comment="hsqldb is earlier than 1:1.8.0.4-3jpp.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071048003" comment="hsqldb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048008" comment="hsqldb-demo is earlier than 1:1.8.0.4-3jpp.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071048009" comment="hsqldb-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048154" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069131" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048010" comment="openoffice.org is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048116" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069061" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048026" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069093" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048104" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069081" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048098" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069143" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048028" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069041" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048072" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069017" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048044" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069037" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048030" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069059" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048040" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069113" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048146" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069137" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048042" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069077" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048060" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069083" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048126" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069011" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048024" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069097" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048128" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069031" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048012" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069091" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048088" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069119" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048132" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069141" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048076" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069023" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048110" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069049" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048084" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069053" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048096" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069021" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048118" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069013" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048062" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069135" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048136" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069149" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048022" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069127" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048152" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069115" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048018" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069109" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048124" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069139" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048144" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069107" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048016" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069099" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048034" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069057" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048066" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069125" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048094" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069025" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048150" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069045" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048148" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069015" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048036" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069007" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048120" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069101" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048122" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069117" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048140" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069063" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048074" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069087" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048106" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069029" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048114" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069095" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048050" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069105" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048130" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069043" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048046" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069085" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048112" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069111" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048056" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069071" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048090" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069035" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048058" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069103" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048102" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069065" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048054" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069073" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048014" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069145" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048068" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048108" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069123" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048020" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069075" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048156" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069005" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048052" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069067" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048038" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069047" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048048" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069079" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048138" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069051" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048086" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069009" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048070" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069039" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048078" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069055" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048092" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069089" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048080" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069147" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048134" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069027" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048142" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069019" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048032" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069129" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048100" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069069" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048082" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069133" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071048064" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070069121" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071049" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1049: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1049-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1049.html" />
          <reference source="CVE" ref_id="CVE-2007-2172" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2172.html" />
          <reference source="CVE" ref_id="CVE-2007-3848" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3848.html" />
          <reference source="CVE" ref_id="CVE-2006-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4538.html" />
          <reference source="CVE" ref_id="CVE-2007-3739" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3739.html" />
          <reference source="CVE" ref_id="CVE-2007-4308" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4308.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system. 

A flaw was found in the handling of process death signals. This allowed a
local user to send arbitrary signals to the suid-process executed by that
user. A successful exploitation of this flaw depends on the structure of
the suid-program and its signal handling. (CVE-2007-3848, Important)

A flaw was found in the IPv4 forwarding base. This allowed a local user to
cause a denial of service. (CVE-2007-2172, Important) 

A flaw was found where a corrupted executable file could cause cross-region
memory mappings on Itanium systems. This allowed a local user to cause a
denial of service. (CVE-2006-4538, Moderate) 

A flaw was found in the stack expansion when using the hugetlb kernel on
PowerPC systems. This allowed a local user to cause a denial of service.
(CVE-2007-3739, Moderate) 

A flaw was found in the aacraid SCSI driver. This allowed a local user to
make ioctl calls to the driver that should be restricted to privileged
users. (CVE-2007-4308, Moderate) 

As well, these updated packages fix the following bug:

* a bug in the TCP header prediction code may have caused "TCP: Treason
uncloaked!" messages to be logged. In certain situations this may have lead
to TCP connections hanging or aborting.

Red Hat Enterprise Linux 3 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-03" />
        <updated date="2007-12-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2172.html">CVE-2007-2172</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3848.html">CVE-2007-3848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4538.html">CVE-2006-4538</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3739.html">CVE-2007-3739</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4308.html">CVE-2007-4308</cve>
                <bugzilla href="http://bugzilla.redhat.com/249237" id="249237">IPV4 'Treason uncloaked' message - hints at a more general kernel/net bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250429" id="250429">CVE-2007-2172 fib_semantics.c out of bounds access vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250972" id="250972">CVE-2007-3848 Privilege escalation via PR_SET_PDEATHSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252309" id="252309">CVE-2007-4308 kernel: Missing ioctl() permission checks in aacraid driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/289151" id="289151">CVE-2006-4538 kernel: Local DoS with corrupted ELF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/294941" id="294941">CVE-2007-3739 LTC36188-Don't allow the stack to grow into hugetlb reserved regions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049004" comment="kernel-source is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436005" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049002" comment="kernel is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049012" comment="kernel-doc is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049018" comment="kernel-hugemem is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049014" comment="kernel-BOOT is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436013" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049008" comment="kernel-unsupported is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070436011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071049006" comment="kernel-smp is earlier than 0:2.4.21-53.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071051" version="505" class="patch">
      <metadata>
        <title>RHSA-2007:1051: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1051-04" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1051.html" />
          <reference source="CVE" ref_id="CVE-2007-5393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5393.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment. This includes kpdf, a PDF file viewer.

Alin Rad Pop discovered a flaw in the handling of PDF files. An attacker
could create a malicious PDF file that would cause kpdf to crash, or
potentially execute arbitrary code when opened. (CVE-2007-5393)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-16" />
        <updated date="2007-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5393.html">CVE-2007-5393</cve>
                <bugzilla href="http://bugzilla.redhat.com/345121" id="345121">CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071051002" comment="kdegraphics is earlier than 7:3.5.4-5.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071051004" comment="kdegraphics-devel is earlier than 7:3.5.4-5.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070729005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071052" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1052: pcre security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1052-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1052.html" />
          <reference source="CVE" ref_id="CVE-2005-4872" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4872.html" />
          <reference source="CVE" ref_id="CVE-2006-7227" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7227.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Flaws were found in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2005-4872, CVE-2006-7227)

Users of PCRE are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-09" />
        <updated date="2007-11-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4872.html">CVE-2005-4872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7227.html">CVE-2006-7227</cve>
                <bugzilla href="http://bugzilla.redhat.com/383341" id="383341">CVE-2006-7227 pcre integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/383361" id="383361">CVE-2005-4872 pcre incorrect memory requirement computation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071052004" comment="pcre-devel is earlier than 0:6.6-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967005" comment="pcre-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071052002" comment="pcre is earlier than 0:6.6-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967003" comment="pcre is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071052009" comment="pcre-devel is earlier than 0:4.5-4.el4_5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071052007" comment="pcre is earlier than 0:4.5-4.el4_5.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071059" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1059: pcre security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1059.html" />
          <reference source="CVE" ref_id="CVE-2006-7225" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7225.html" />
          <reference source="CVE" ref_id="CVE-2006-7226" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7226.html" />
          <reference source="CVE" ref_id="CVE-2006-7228" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7228.html" />
          <reference source="CVE" ref_id="CVE-2006-7230" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7230.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Flaws were discovered in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may have been possible to run
arbitrary code as the user running the application.
(CVE-2006-7225, CVE-2006-7226, CVE-2006-7228, CVE-2006-7230)

Users of PCRE are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.

Red Hat would like to thank Ludwig Nussel for reporting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-29" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7225.html">CVE-2006-7225</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7226.html">CVE-2006-7226</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7228.html">CVE-2006-7228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7230.html">CVE-2006-7230</cve>
                <bugzilla href="http://bugzilla.redhat.com/383371" id="383371">CVE-2006-7228 pcre integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384761" id="384761">CVE-2006-7225 pcre miscalculation of memory requirements for malformed Posix character class</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384781" id="384781">CVE-2006-7226 pcre miscalculation of memory requirements for repeated subpattern containing a named recursion or subroutine reference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384801" id="384801">CVE-2006-7230 pcre miscalculation of memory requirements if options are changed during pattern compilation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071059004" comment="pcre-devel is earlier than 0:6.6-2.el5_1.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967005" comment="pcre-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071059002" comment="pcre is earlier than 0:6.6-2.el5_1.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070967003" comment="pcre is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071063" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1063: pcre security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1063-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1063.html" />
          <reference source="CVE" ref_id="CVE-2006-7228" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7228.html" />
          <reference source="CVE" ref_id="CVE-2007-1660" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1660.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Flaws were discovered in the way PCRE handles certain malformed regular
expressions.  If an application linked against PCRE, such as Konqueror,
parsed a malicious regular expression, it may have been possible to run
arbitrary code as the user running the application. (CVE-2006-7228,
CVE-2007-1660)

Users of PCRE are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.

Red Hat would like to thank Ludwig Nussel for reporting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-29" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7228.html">CVE-2006-7228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1660.html">CVE-2007-1660</cve>
                <bugzilla href="http://bugzilla.redhat.com/315881" id="315881">CVE-2007-1660 pcre regular expression flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/383371" id="383371">CVE-2006-7228 pcre integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071063004" comment="pcre-devel is earlier than 0:3.9-10.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071063002" comment="pcre is earlier than 0:3.9-10.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071068" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1068: pcre security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1068-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1068.html" />
          <reference source="CVE" ref_id="CVE-2006-7225" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7225.html" />
          <reference source="CVE" ref_id="CVE-2006-7226" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7226.html" />
          <reference source="CVE" ref_id="CVE-2006-7228" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7228.html" />
          <reference source="CVE" ref_id="CVE-2006-7230" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7230.html" />
          <reference source="CVE" ref_id="CVE-2007-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1659.html" />
    
    <description>PCRE is a Perl-compatible regular expression library.

Flaws were discovered in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may have been possible to run
arbitrary code as the user running the application.
(CVE-2006-7225, CVE-2006-7226, CVE-2006-7228, CVE-2006-7230, CVE-2007-1659)

Users of PCRE are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.

Red Hat would like to thank Ludwig Nussel for reporting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-29" />
        <updated date="2007-11-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7225.html">CVE-2006-7225</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7226.html">CVE-2006-7226</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7228.html">CVE-2006-7228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7230.html">CVE-2006-7230</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1659.html">CVE-2007-1659</cve>
                <bugzilla href="http://bugzilla.redhat.com/315871" id="315871">CVE-2007-1659 pcre regular expression flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/383371" id="383371">CVE-2006-7228 pcre integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384761" id="384761">CVE-2006-7225 pcre miscalculation of memory requirements for malformed Posix character class</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384781" id="384781">CVE-2006-7226 pcre miscalculation of memory requirements for repeated subpattern containing a named recursion or subroutine reference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/384801" id="384801">CVE-2006-7230 pcre miscalculation of memory requirements if options are changed during pattern compilation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071068004" comment="pcre-devel is earlier than 0:4.5-4.el4_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968005" comment="pcre-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071068002" comment="pcre is earlier than 0:4.5-4.el4_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070968003" comment="pcre is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071076" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1076: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1076-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1076.html" />
          <reference source="CVE" ref_id="CVE-2006-7228" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7228.html" />
          <reference source="CVE" ref_id="CVE-2007-2052" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2052.html" />
          <reference source="CVE" ref_id="CVE-2007-4965" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4965.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

An integer overflow flaw was discovered in the way Python's pcre module
handled certain regular expressions. If a Python application used the pcre
module to compile and execute untrusted regular expressions, it may be
possible to cause the application to crash, or allow arbitrary code
execution with the privileges of the Python interpreter. (CVE-2006-7228)

A flaw was discovered in the strxfrm() function of Python's locale module.
Strings generated by this function were not properly NULL-terminated. This
may possibly cause disclosure of data stored in the memory of a Python
application using this function. (CVE-2007-2052)

Multiple integer overflow flaws were discovered in Python's imageop module.
If an application written in Python used the imageop module to process
untrusted images, it could cause the application to crash, enter an
infinite loop, or possibly execute arbitrary code with the privileges of
the Python interpreter. (CVE-2007-4965)

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-10" />
        <updated date="2007-12-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7228.html">CVE-2006-7228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2052.html">CVE-2007-2052</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4965.html">CVE-2007-4965</cve>
                <bugzilla href="http://bugzilla.redhat.com/235093" id="235093">CVE-2007-2052 python off-by-one locale.strxfrm() (possible memory disclosure)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/295971" id="295971">CVE-2007-4965 python imageop module heap corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/383371" id="383371">CVE-2006-7228 pcre integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076008" comment="python-devel is earlier than 0:2.2.3-6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076009" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076004" comment="python-docs is earlier than 0:2.2.3-6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076005" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076010" comment="tkinter is earlier than 0:2.2.3-6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076002" comment="python is earlier than 0:2.2.3-6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076006" comment="python-tools is earlier than 0:2.2.3-6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076014" comment="python-devel is earlier than 0:2.3.4-14.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076009" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076017" comment="python-docs is earlier than 0:2.3.4-14.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076005" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076015" comment="tkinter is earlier than 0:2.3.4-14.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076011" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076013" comment="python is earlier than 0:2.3.4-14.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071076016" comment="python-tools is earlier than 0:2.3.4-14.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071076007" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071078" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1078: cairo security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1078-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1078.html" />
          <reference source="CVE" ref_id="CVE-2007-5503" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5503.html" />
    
    <description>Cairo is a vector graphics library designed to provide high-quality display
and print output.

An integer overflow flaw was found in the way Cairo processes PNG images.
If an application linked against Cairo processes a malicious PNG image, it
is possible to execute arbitrary code as the user running the application.
(CVE-2007-5503)

Users of Cairo are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-29" />
        <updated date="2007-11-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5503.html">CVE-2007-5503</cve>
                <bugzilla href="http://bugzilla.redhat.com/387431" id="387431">CVE-2007-5503 cairo integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071078004" comment="cairo-devel is earlier than 0:1.2.4-3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071078005" comment="cairo-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071078002" comment="cairo is earlier than 0:1.2.4-3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071078003" comment="cairo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071082" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1082: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1082-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1082.html" />
          <reference source="CVE" ref_id="CVE-2007-5947" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5947.html" />
          <reference source="CVE" ref_id="CVE-2007-5959" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5959.html" />
          <reference source="CVE" ref_id="CVE-2007-5960" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5960.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A cross-site scripting flaw was found in the way Firefox handled the
jar: URI scheme. It was possible for a malicious website to leverage this
flaw and conduct a cross-site scripting attack against a user running
Firefox. (CVE-2007-5947)

Several flaws were found in the way Firefox processed certain malformed web
content. A webpage containing malicious content could cause Firefox to
crash, or potentially execute arbitrary code as the user running Firefox.
(CVE-2007-5959)

A race condition existed when Firefox set the "window.location" property
for a webpage. This flaw could allow a webpage to set an arbitrary Referer
header, which may lead to a Cross-site Request Forgery (CSRF) attack
against websites that rely only on the Referer header for protection.
(CVE-2007-5960)

Users of Firefox are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-11-26" />
        <updated date="2007-11-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5947.html">CVE-2007-5947</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5959.html">CVE-2007-5959</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5960.html">CVE-2007-5960</cve>
                <bugzilla href="http://bugzilla.redhat.com/394211" id="394211">CVE-2007-5947 Mozilla jar: protocol XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394241" id="394241">CVE-2007-5959 Multiple flaws in Firefox</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394261" id="394261">CVE-2007-5960 Mozilla Cross-site Request Forgery flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071082004" comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097011" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071082002" comment="firefox is earlier than 0:1.5.0.12-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070097009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071082007" comment="firefox is earlier than 0:1.5.0.12-0.8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070079003" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071083" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1083: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1083-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1083.html" />
          <reference source="CVE" ref_id="CVE-2007-5947" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5947.html" />
          <reference source="CVE" ref_id="CVE-2007-5959" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5959.html" />
          <reference source="CVE" ref_id="CVE-2007-5960" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5960.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A cross-site scripting flaw was found in the way Thunderbird handled the
jar: URI scheme. It may be possible for a malicious HTML mail message to
leverage this flaw, and conduct a cross-site scripting attack against a
user running Thunderbird. (CVE-2007-5947)

Several flaws were found in the way Thunderbird processed certain malformed
HTML mail content. A HTML mail message containing malicious content could
cause Thunderbird to crash, or potentially execute arbitrary code as the
user running Thunderbird. (CVE-2007-5959)

A race condition existed when Thunderbird set the "window.location"
property when displaying HTML mail content. This flaw could allow a HTML
mail message to set an arbitrary Referer header, which may lead to a
Cross-site Request Forgery (CSRF) attack against websites that rely only on
the Referer header for protection. (CVE-2007-5960) 

All users of thunderbird are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-19" />
        <updated date="2007-12-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5947.html">CVE-2007-5947</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5959.html">CVE-2007-5959</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5960.html">CVE-2007-5960</cve>
                <bugzilla href="http://bugzilla.redhat.com/394211" id="394211">CVE-2007-5947 Mozilla jar: protocol XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394241" id="394241">CVE-2007-5959 Multiple flaws in Firefox</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394261" id="394261">CVE-2007-5960 Mozilla Cross-site Request Forgery flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071083002" comment="thunderbird is earlier than 0:1.5.0.12-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070108003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071083005" comment="thunderbird is earlier than 0:1.5.0.12-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070078003" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071084" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1084: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1084-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1084.html" />
          <reference source="CVE" ref_id="CVE-2007-5947" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5947.html" />
          <reference source="CVE" ref_id="CVE-2007-5959" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5959.html" />
          <reference source="CVE" ref_id="CVE-2007-5960" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5960.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A cross-site scripting flaw was found in the way SeaMonkey handled the
jar: URI scheme. It was possible for a malicious website to leverage this
flaw and conduct a cross-site scripting attack against a user running
SeaMonkey. (CVE-2007-5947)

Several flaws were found in the way SeaMonkey processed certain malformed
web content. A webpage containing malicious content could cause SeaMonkey
to crash, or potentially execute arbitrary code as the user running
SeaMonkey. (CVE-2007-5959)

A race condition existed when Seamonkey set the "window.location" property
for a webpage. This flaw could allow a webpage to set an arbitrary Referer
header, which may lead to a Cross-site Request Forgery (CSRF) attack
against websites that rely only on the Referer header for protection.
(CVE-2007-5960)

Users of SeaMonkey are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-11-26" />
        <updated date="2008-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5947.html">CVE-2007-5947</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5959.html">CVE-2007-5959</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5960.html">CVE-2007-5960</cve>
                <bugzilla href="http://bugzilla.redhat.com/394211" id="394211">CVE-2007-5947 Mozilla jar: protocol XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394241" id="394241">CVE-2007-5959 Multiple flaws in Firefox</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/394261" id="394261">CVE-2007-5960 Mozilla Cross-site Request Forgery flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084018" comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084020" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084014" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084012" comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084002" comment="seamonkey is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084004" comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084016" comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084008" comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084024" comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077009" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084031" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077019" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084026" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077021" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084025" comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077005" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084023" comment="seamonkey is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084032" comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084030" comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077015" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084029" comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077007" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084028" comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077013" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071084027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070077011" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071090" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1090: openoffice.org2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1090.html" />
          <reference source="CVE" ref_id="CVE-2007-4575" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4575.html" />
    
    <description>OpenOffice.org is an office productivity suite.
HSQLDB is the default database engine shipped with OpenOffice.org 2.

It was discovered that HSQLDB could allow the execution of arbitrary public
static Java methods.  A carefully crafted odb file opened in OpenOffice.org
Base could execute arbitrary commands with the permissions of the user
running OpenOffice.org. (CVE-2007-4575)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-05" />
        <updated date="2007-12-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4575.html">CVE-2007-4575</cve>
                <bugzilla href="http://bugzilla.redhat.com/299801" id="299801">CVE-2007-4575 OpenOffice.org-base allows Denial-of-Service and command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090118" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406208" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090076" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406188" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090070" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406198" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090066" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406196" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090024" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406254" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090020" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406246" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090018" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406234" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090008" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406172" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090078" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406224" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090060" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406248" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090050" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406212" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090046" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406166" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090012" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406256" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090116" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406278" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090088" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406190" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090044" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406216" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090056" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406192" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090038" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406178" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090014" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406266" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090030" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406194" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090002" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406164" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090112" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406174" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090110" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406260" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090100" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406280" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090092" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406250" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090086" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406270" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090084" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406264" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090080" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406186" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090074" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406258" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090048" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406228" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090026" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406210" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090022" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406274" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090016" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406236" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090108" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406252" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090094" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406200" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090064" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406202" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090042" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406214" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090006" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406180" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090104" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406170" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090102" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406242" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090098" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406244" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090058" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406184" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090054" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406238" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090040" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406222" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090010" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406204" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090004" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406262" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090114" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406176" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090096" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406276" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090036" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406220" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090034" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406230" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090106" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406268" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090090" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406168" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090082" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406226" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090072" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406218" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090068" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406206" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090062" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406272" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090052" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406232" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090032" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406240" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071090028" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.3.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070406182" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071095" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1095: htdig security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1095.html" />
          <reference source="CVE" ref_id="CVE-2007-6110" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6110.html" />
    
    <description>The ht://Dig system is a complete World Wide Web indexing and searching
system for a small domain or intranet.

A cross-site scripting flaw was discovered in a htdig search page. An
attacker could construct a carefully crafted URL, which once visited by an 
unsuspecting user, could cause a user's Web browser to execute malicious
script in the context of the visited htdig search Web page. (CVE-2007-6110)

Users of htdig are advised to upgrade to these updated packages, which
contain backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-03" />
        <updated date="2007-12-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6110.html">CVE-2007-6110</cve>
                <bugzilla href="http://bugzilla.redhat.com/399561" id="399561">CVE-2007-6110 htdig htsearch XSS vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071095002" comment="htdig is earlier than 3:3.2.0b6-9.0.1.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071095003" comment="htdig is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071095004" comment="htdig-web is earlier than 3:3.2.0b6-9.0.1.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071095005" comment="htdig-web is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071095007" comment="htdig is earlier than 3:3.2.0b6-4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071095008" comment="htdig is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071095009" comment="htdig-web is earlier than 3:3.2.0b6-4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071095010" comment="htdig-web is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071104" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1104: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1104.html" />
          <reference source="CVE" ref_id="CVE-2007-4997" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4997.html" />
          <reference source="CVE" ref_id="CVE-2007-5494" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5494.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system. 

These updated packages fix the following security issues:

A flaw was found in the handling of IEEE 802.11 frames, which affected
several wireless LAN modules. In certain situations, a remote attacker
could trigger this flaw by sending a malicious packet over a wireless
network, causing a denial of service (kernel crash).
(CVE-2007-4997, Important)

A memory leak was found in the Red Hat Content Accelerator kernel patch.
A local user could use this flaw to cause a denial of service (memory
exhaustion). (CVE-2007-5494, Important)

Additionally, the following bugs were fixed:

* when running the "ls -la" command on an NFSv4 mount point, incorrect
file attributes, and outdated file size and timestamp information were
returned. As well, symbolic links may have been displayed as actual files.

* a bug which caused the cmirror write path to appear deadlocked after a
successful recovery, which may have caused syncing to hang, has been
resolved.

* a kernel panic which occurred when manually configuring LCS interfaces on
the IBM S/390 has been resolved.

* when running a 32-bit binary on a 64-bit system, it was possible to
mmap page at address 0 without flag MAP_FIXED set. This has been
resolved in these updated packages.

* the Non-Maskable Interrupt (NMI) Watchdog did not increment the NMI
interrupt counter in "/proc/interrupts" on systems running an AMD Opteron
CPU. This caused systems running NMI Watchdog to restart at regular
intervals.

* a bug which caused the diskdump utility to run very slowly on devices
using Fusion MPT has been resolved.

All users are advised to upgrade to these updated packages, which resolve
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-19" />
        <updated date="2007-12-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4997.html">CVE-2007-4997</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5494.html">CVE-2007-5494</cve>
                <bugzilla href="http://bugzilla.redhat.com/315051" id="315051">CVE-2007-5494 open(O_ATOMICLOOKUP) leaks dentry</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/346341" id="346341">CVE-2007-4997 kernel ieee80211 off-by-two integer underflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/371551" id="371551">NFS problem#3 of IT 106473 - 32-bit jiffy wrap around - NFS inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/399661" id="399661">cmirror write path appears deadlocked after recovery is successful</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/400801" id="400801">LTC39618-kernel panic making lcs interfaces online on LPAR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/400811" id="400811">[RHEL4] Odd behaviour in mmap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/404741" id="404741">[RHEL4] NMI Watchdog Not Working in RHEL 4 U6 Opteron Systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/404781" id="404781">RHEL4.6 [REGRESSION] diskdump works with mpt fusion too slow.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104002" comment="kernel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104022" comment="kernel-doc is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014019" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104004" comment="kernel-devel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104016" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104020" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014015" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104014" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014011" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014009" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104010" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488011" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104006" comment="kernel-xenU is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070488009" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071104012" comment="kernel-smp is earlier than 0:2.6.9-67.0.1.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070014013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071114" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1114: samba security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1114-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1114.html" />
          <reference source="CVE" ref_id="CVE-2007-6015" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6015.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A stack buffer overflow flaw was found in the way Samba authenticates
remote users. A remote unauthenticated user could trigger this flaw to
cause the Samba server to crash, or execute arbitrary code with the
permissions of the Samba server. (CVE-2007-6015)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

This update also fixes a regression caused by the fix for CVE-2007-4572,
which prevented some clients from being able to properly access shares.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2007-12-10" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6015.html">CVE-2007-6015</cve>
                <bugzilla href="http://bugzilla.redhat.com/389021" id="389021">Critical Regression caused by CVE-2007-4572</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396401" id="396401">CVE-2007-6015 samba: send_mailslot() buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/407071" id="407071">Critical Regression caused by CVE-2007-4572</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/407081" id="407081">Critical Regression caused by CVE-2007-4572</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114008" comment="samba-client is earlier than 0:3.0.25b-1.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114006" comment="samba-common is earlier than 0:3.0.25b-1.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061005" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114002" comment="samba is earlier than 0:3.0.25b-1.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114004" comment="samba-swat is earlier than 0:3.0.25b-1.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070061007" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114013" comment="samba-client is earlier than 0:3.0.9-1.3E.14.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114017" comment="samba-common is earlier than 0:3.0.9-1.3E.14.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114011" comment="samba is earlier than 0:3.0.9-1.3E.14.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114015" comment="samba-swat is earlier than 0:3.0.9-1.3E.14.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114022" comment="samba-client is earlier than 0:3.0.25b-1.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114023" comment="samba-common is earlier than 0:3.0.25b-1.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114020" comment="samba is earlier than 0:3.0.25b-1.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071114021" comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071126" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1126: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1126-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1126.html" />
          <reference source="CVE" ref_id="CVE-2007-5275" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5275.html" />
          <reference source="CVE" ref_id="CVE-2007-4324" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4324.html" />
          <reference source="CVE" ref_id="CVE-2007-4768" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4768.html" />
          <reference source="CVE" ref_id="CVE-2007-6242" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6242.html" />
          <reference source="CVE" ref_id="CVE-2007-6243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6243.html" />
          <reference source="CVE" ref_id="CVE-2007-6244" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6244.html" />
          <reference source="CVE" ref_id="CVE-2007-6245" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6245.html" />
          <reference source="CVE" ref_id="CVE-2007-6246" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6246.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

Several input validation flaws were found in the way Flash Player displays
certain content. It may be possible to execute arbitrary code on a victim's
machine, if the victim opens a malicious Adobe Flash file. 
(CVE-2007-4768, CVE-2007-6242, CVE-2007-6246)

A flaw was found in the way Flash Player handled the asfunction: protocol.
Malformed SWF files could perform a cross-site scripting attack.
(CVE-2007-6244)

A flaw was found in the way Flash Player modified HTTP request headers.
Malicious content could allow Flash Player to conduct a HTTP response
splitting attack. (CVE-2007-6245)

A flaw was found in the way Flash Player processes certain SWF content. A
malicious SWF file could allow a remote attacker to conduct a port scanning
attack from the client's machine. (CVE-2007-4324)

A flaw was found in the way Flash Player establishes TCP sessions. A remote
attacker could use Flash Player to conduct a DNS rebinding attack.
(CVE-2007-5275) 

Users of Adobe Flash Player are advised to upgrade to this updated package,
which contains version 9.0.115.0 and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-18" />
        <updated date="2007-12-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5275.html">CVE-2007-5275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4324.html">CVE-2007-4324</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4768.html">CVE-2007-4768</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6242.html">CVE-2007-6242</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6243.html">CVE-2007-6243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6244.html">CVE-2007-6244</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6245.html">CVE-2007-6245</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6246.html">CVE-2007-6246</cve>
                <bugzilla href="http://bugzilla.redhat.com/252292" id="252292">CVE-2007-4324 Flash movie can determine whether a TCP port is open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/367501" id="367501">CVE-2007-5275 Flash plugin DNS rebinding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/392911" id="392911">CVE-2007-4768: pcre before 7.3 incorrect unicode in char class optimization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412161" id="412161">CVE-2007-6242 flash: abitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414501" id="414501">CVE-2007-6244 flash: XSS via asfunction protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414511" id="414511">CVE-2007-6245 flash: HTTP headers modification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414521" id="414521">CVE-2007-6246 flash: privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071126002" comment="flash-plugin is earlier than 0:9.0.115.0-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070696003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071128" version="503" class="patch">
      <metadata>
        <title>RHSA-2007:1128: autofs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1128-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1128.html" />
          <reference source="CVE" ref_id="CVE-2007-5964" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5964.html" />
    
    <description>The autofs utility controls the operation of the automount daemon, which
automatically mounts and unmounts file systems after a period of
inactivity. 

There was a security issue with the default installed configuration of
autofs version 5 whereby the entry for the "hosts" map did not specify the
"nosuid" mount option.  A local user with control of a remote nfs server
could create a setuid root executable within an exported filesystem on the
remote nfs server that, if mounted using the default hosts map, would allow
the user to gain root privileges. (CVE-2007-5964) 

Due to the fact that autofs always mounted hosts map entries suid by
default, autofs has now been altered to always use the "nosuid" option when
mounting from the default hosts map. The "suid" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the hosts map which corresponds to the /net entry in the
default configuration.

Users are advised to upgrade to these updated autofs packages, which
resolve this issue.

Red Hat would like to thank Josh Lange for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-12" />
        <updated date="2007-12-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5964.html">CVE-2007-5964</cve>
                <bugzilla href="http://bugzilla.redhat.com/410031" id="410031">CVE-2007-5964 autofs defaults don't restrict suid in /net</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071128002" comment="autofs is earlier than 1:5.0.1-0.rc2.55.el5.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071128003" comment="autofs is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071129" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1129: autofs5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1129-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1129.html" />
          <reference source="CVE" ref_id="CVE-2007-5964" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5964.html" />
    
    <description>The autofs utility controls the operation of the automount daemon, which
automatically mounts and unmounts file systems after a period of
inactivity.  The autofs version 5 package was made available as a
technology preview in Red Hat Enterprise Linux version 4.6.

There was a security issue with the default installed configuration of
autofs version 5 whereby the entry for the "hosts" map did not specify the
"nosuid" mount option. A local user with control of a remote nfs server
could create a setuid root executable within an exported filesystem on the
remote nfs server that, if mounted using the default hosts map, would allow
the user to gain root privileges. (CVE-2007-5964)

Due to the fact that autofs version 5 always mounted hosts map entries suid
by default, autofs has now been altered to always use the "nosuid" option
when mounting from the default hosts map. The "suid" option must be
explicitly given in the master map entry to revert to the old behavior.
This change affects only the hosts map which corresponds to the /net entry
in the default configuration.

Users are advised to upgrade to these updated autofs5 packages, which
resolve this issue.

Red Hat would like to thank Josh Lange for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-12" />
        <updated date="2007-12-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5964.html">CVE-2007-5964</cve>
                <bugzilla href="http://bugzilla.redhat.com/410031" id="410031">CVE-2007-5964 autofs defaults don't restrict suid in /net</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071129002" comment="autofs5 is earlier than 1:5.0.1-0.rc2.55.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071129003" comment="autofs5 is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071130" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1130: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1130-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1130.html" />
          <reference source="CVE" ref_id="CVE-2007-6239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6239.html" />
    
    <description>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A flaw was found in the way squid stored HTTP headers for cached objects
in system memory. An attacker could cause squid to use additional memory,
and trigger high CPU usage when processing requests for certain cached
objects, possibly leading to a denial of service. (CVE-2007-6239)

Users of squid are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-18" />
        <updated date="2007-12-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6239.html">CVE-2007-6239</cve>
                <bugzilla href="http://bugzilla.redhat.com/410181" id="410181">CVE-2007-6239 squid: DoS in cache updates</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071130002" comment="squid is earlier than 7:2.6.STABLE6-5.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070131003" comment="squid is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001001" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071130005" comment="squid is earlier than 7:2.5.STABLE3-8.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071130006" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071130008" comment="squid is earlier than 7:2.5.STABLE14-1.4E.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071130006" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071155" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1155: mysql security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1155-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1155.html" />
          <reference source="CVE" ref_id="CVE-2007-5969" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5969.html" />
          <reference source="CVE" ref_id="CVE-2007-5925" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5925.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

A flaw was found in a way MySQL handled symbolic links when database tables
were created with explicit "DATA" and "INDEX DIRECTORY" options. An
authenticated user could create a table that would overwrite tables in
other databases, causing destruction of data or allowing the user to
elevate privileges. (CVE-2007-5969)

A flaw was found in a way MySQL's InnoDB engine handled spatial indexes. An
authenticated user could create a table with spatial indexes, which are not
supported by the InnoDB engine, that would cause the mysql daemon to crash
when used. This issue only causes a temporary denial of service, as the
mysql daemon will be automatically restarted after the crash.
(CVE-2007-5925)

All mysql users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-18" />
        <updated date="2007-12-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5969.html">CVE-2007-5969</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5925.html">CVE-2007-5925</cve>
                <bugzilla href="http://bugzilla.redhat.com/377451" id="377451">CVE-2007-5925 mysql DoS in the InnoDB Engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397071" id="397071">CVE-2007-5969 mysql: possible system table information overwrite using symlinks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155004" comment="mysql-test is earlier than 0:5.0.22-2.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875011" comment="mysql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155002" comment="mysql is earlier than 0:5.0.22-2.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875003" comment="mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155006" comment="mysql-server is earlier than 0:5.0.22-2.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875007" comment="mysql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155010" comment="mysql-bench is earlier than 0:5.0.22-2.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875009" comment="mysql-bench is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155008" comment="mysql-devel is earlier than 0:5.0.22-2.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070875005" comment="mysql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155013" comment="mysql is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155015" comment="mysql-server is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152009" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155019" comment="mysql-bench is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152007" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071155017" comment="mysql-devel is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070152005" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071165" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1165: libexif security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1165.html" />
          <reference source="CVE" ref_id="CVE-2007-6351" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6351.html" />
          <reference source="CVE" ref_id="CVE-2007-6352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6352.html" />
    
    <description>The libexif packages contain the Exif library. Exif is an image file format
specification that enables metadata tags to be added to existing JPEG, TIFF
and RIFF files. The Exif library makes it possible to parse an Exif file
and read this metadata.

An infinite recursion flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to crash. (CVE-2007-6351)

An integer overflow flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to execute arbitrary code, or crash.
(CVE-2007-6352)

Users of libexif are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-19" />
        <updated date="2007-12-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6351.html">CVE-2007-6351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6352.html">CVE-2007-6352</cve>
                <bugzilla href="http://bugzilla.redhat.com/425551" id="425551">CVE-2007-6351 libexif infinite recursion flaw (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425561" id="425561">CVE-2007-6352 libexif integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071165004" comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501005" comment="libexif-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071165002" comment="libexif is earlier than 0:0.6.13-4.0.2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501003" comment="libexif is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071166" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1166: libexif security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1166-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1166.html" />
          <reference source="CVE" ref_id="CVE-2007-6352" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6352.html" />
    
    <description>The libexif packages contain the Exif library. Exif is an image file format
specification that enables metadata tags to be added to existing JPEG, TIFF
and RIFF files. The Exif library makes it possible to parse an Exif file
and read this metadata.

An integer overflow flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to execute arbitrary code, or crash.
(CVE-2007-6352)

Users of libexif are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-19" />
        <updated date="2007-12-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6352.html">CVE-2007-6352</cve>
                <bugzilla href="http://bugzilla.redhat.com/425561" id="425561">CVE-2007-6352 libexif integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071166004" comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501010" comment="libexif-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20071166002" comment="libexif is earlier than 0:0.5.12-5.1.0.2.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20070501008" comment="libexif is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071176" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1176: autofs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1176.html" />
          <reference source="CVE" ref_id="CVE-2007-6285" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6285.html" />
    
    <description>The autofs utility controls the operation of the automount daemon, which
automatically mounts file systems when you use them, and unmounts them when
you are not using them. This can include network file systems and CD-ROMs.

There was a security issue with the default configuration of autofs version
5, whereby the entry for the "-hosts" map did not specify the "nodev" mount
option. A local user with control of a remote NFS server could create
special device files on the remote file system, that if mounted using the
default "-hosts" map, could allow the user to access important system
devices. (CVE-2007-6285)

This issue is similar to CVE-2007-5964, which fixed a missing "nosuid"
mount option in autofs. Both the "nodev" and "nosuid" options should be
enabled to prevent a possible compromise of machine integrity.

Due to the fact that autofs always mounted "-hosts" map entries "dev" by
default, autofs has now been altered to always use the "nodev" option when
mounting from the default "-hosts" map. The "dev" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the "-hosts" map which corresponds to the "/net" entry in the
default configuration.

All autofs users are advised to upgrade to these updated packages, which
resolve this issue.

Red Hat would like to thank Tim Baum for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-20" />
        <updated date="2007-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6285.html">CVE-2007-6285</cve>
                <bugzilla href="http://bugzilla.redhat.com/426218" id="426218">CVE-2007-6285 autofs default doesn't set nodev in /net</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071176002" comment="autofs is earlier than 1:5.0.1-0.rc2.55.el5.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071128003" comment="autofs is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20071177" version="502" class="patch">
      <metadata>
        <title>RHSA-2007:1177: autofs5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2007:1177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2007-1177.html" />
          <reference source="CVE" ref_id="CVE-2007-6285" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6285.html" />
    
    <description>The autofs utility controls the operation of the automount daemon, which
automatically mounts file systems when you use them, and unmounts them when
you are not using them. This can include network file systems and CD-ROMs.
The autofs5 packages were made available as a technology preview in Red Hat
Enterprise Linux 4.6.

There was a security issue with the default configuration of autofs version
5, whereby the entry for the "-hosts" map did not specify the "nodev" mount
option. A local user with control of a remote NFS server could create
special device files on the remote file system, that if mounted using the
default "-hosts" map, could allow the user to access important system
devices. (CVE-2007-6285)

This issue is similar to CVE-2007-5964, which fixed a missing "nosuid"
mount option in autofs. Both the "nodev" and "nosuid" options should be
enabled to prevent a possible compromise of machine integrity.

Due to the fact that autofs always mounted "-hosts" map entries "dev" by
default, autofs has now been altered to always use the "nodev" option when
mounting from the default "-hosts" map. The "dev" option must be explicitly
given in the master map entry to revert to the old behavior. This change
affects only the "-hosts" map which corresponds to the "/net" entry in the
default configuration.

All autofs5 users are advised to upgrade to these updated packages, which
resolve this issue.

Red Hat would like to thank Tim Baum for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-12-20" />
        <updated date="2007-12-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6285.html">CVE-2007-6285</cve>
                <bugzilla href="http://bugzilla.redhat.com/426218" id="426218">CVE-2007-6285 autofs default doesn't set nodev in /net</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20070001008" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071177002" comment="autofs5 is earlier than 1:5.0.1-0.rc2.55.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20071129003" comment="autofs5 is signed with Red Hat master key" />
 
</criteria>

    </definition>
</definitions>

<tests>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001001" version="502" comment="Red Hat Enterprise Linux 3 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001002" version="502" comment="openoffice.org is earlier than 0:1.1.2-35.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001003" version="502" comment="openoffice.org is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001004" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-35.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001005" version="502" comment="openoffice.org-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001006" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-35.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001007" version="502" comment="openoffice.org-i18n is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001008" version="502" comment="Red Hat Enterprise Linux 4 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001009" version="502" comment="openoffice.org is earlier than 0:1.1.5-6.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001010" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001011" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001012" version="502" comment="openoffice.org-kde is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070001013" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002002" version="502" comment="XFree86 is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002003" version="502" comment="XFree86 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002004" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002005" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002006" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002007" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002008" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002009" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002010" version="502" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002011" version="502" comment="XFree86-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002012" version="502" comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002013" version="502" comment="XFree86-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002014" version="502" comment="XFree86-doc is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002015" version="502" comment="XFree86-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002016" version="502" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002017" version="502" comment="XFree86-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002018" version="502" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002019" version="502" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002020" version="502" comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002021" version="502" comment="XFree86-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002022" version="502" comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002023" version="502" comment="XFree86-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002024" version="502" comment="XFree86-tools is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002025" version="502" comment="XFree86-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002026" version="502" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002027" version="502" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002028" version="502" comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002029" version="502" comment="XFree86-base-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002030" version="502" comment="XFree86-devel is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002031" version="502" comment="XFree86-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002032" version="502" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002033" version="502" comment="XFree86-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002034" version="502" comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002035" version="502" comment="XFree86-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002036" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002037" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002038" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002039" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002040" version="502" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002041" version="502" comment="XFree86-truetype-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002042" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002043" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002044" version="502" comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002045" version="502" comment="XFree86-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002046" version="502" comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002047" version="502" comment="XFree86-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002048" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002049" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002050" version="502" comment="XFree86-twm is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002051" version="502" comment="XFree86-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002052" version="502" comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002053" version="502" comment="XFree86-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002054" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002055" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002056" version="502" comment="XFree86-libs is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002057" version="502" comment="XFree86-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002058" version="502" comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002059" version="502" comment="XFree86-libs-data is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002060" version="502" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070002061" version="502" comment="XFree86-syriac-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003002" version="502" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003003" version="502" comment="xorg-x11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003004" version="502" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003005" version="502" comment="xorg-x11-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003006" version="502" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003007" version="502" comment="xorg-x11-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003008" version="502" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003009" version="502" comment="xorg-x11-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003010" version="502" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003011" version="502" comment="xorg-x11-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003012" version="502" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003013" version="502" comment="xorg-x11-Xdmx is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003014" version="502" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003015" version="502" comment="xorg-x11-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003016" version="502" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003017" version="502" comment="xorg-x11-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003018" version="502" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003019" version="502" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003020" version="502" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003021" version="502" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003022" version="502" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003023" version="502" comment="xorg-x11-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003024" version="502" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003025" version="502" comment="xorg-x11-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003026" version="502" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003027" version="502" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003028" version="502" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003029" version="502" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003030" version="502" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003031" version="502" comment="xorg-x11-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003032" version="502" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003033" version="502" comment="xorg-x11-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003034" version="502" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003035" version="502" comment="xorg-x11-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003036" version="502" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070003037" version="502" comment="xorg-x11-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008002" version="502" comment="dbus is earlier than 0:0.22-12.EL.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008003" version="502" comment="dbus is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008004" version="502" comment="dbus-devel is earlier than 0:0.22-12.EL.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008005" version="502" comment="dbus-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008006" version="502" comment="dbus-python is earlier than 0:0.22-12.EL.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008007" version="502" comment="dbus-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008008" version="502" comment="dbus-glib is earlier than 0:0.22-12.EL.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008009" version="502" comment="dbus-glib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008010" version="502" comment="dbus-x11 is earlier than 0:0.22-12.EL.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070008011" version="502" comment="dbus-x11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070008006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011002" version="502" comment="libgsf is earlier than 0:1.6.0-7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011003" version="502" comment="libgsf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011004" version="502" comment="libgsf-devel is earlier than 0:1.6.0-7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011005" version="502" comment="libgsf-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011007" version="502" comment="libgsf is earlier than 0:1.10.1-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070011005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070011008" version="502" comment="libgsf-devel is earlier than 0:1.10.1-2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070011005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014002" version="502" comment="kernel is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014003" version="502" comment="kernel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014004" version="502" comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014005" version="502" comment="kernel-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014006" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014007" version="502" comment="kernel-smp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014008" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014009" version="502" comment="kernel-largesmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014010" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014011" version="502" comment="kernel-largesmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014012" version="502" comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014013" version="502" comment="kernel-smp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014014" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014015" version="502" comment="kernel-hugemem is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014016" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014017" version="502" comment="kernel-hugemem-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014018" version="502" comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070014019" version="502" comment="kernel-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015002" version="502" comment="ImageMagick is earlier than 0:5.5.6-24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015003" version="502" comment="ImageMagick is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015004" version="502" comment="ImageMagick-devel is earlier than 0:5.5.6-24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015005" version="502" comment="ImageMagick-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015006" version="502" comment="ImageMagick-perl is earlier than 0:5.5.6-24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015007" version="502" comment="ImageMagick-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015008" version="502" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015009" version="502" comment="ImageMagick-c++-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015010" version="502" comment="ImageMagick-c++ is earlier than 0:5.5.6-24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015011" version="502" comment="ImageMagick-c++ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015013" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015014" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015015" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015016" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070015017" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070015005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070018002" version="502" comment="fetchmail is earlier than 0:6.2.0-3.el3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070018003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070018003" version="502" comment="fetchmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070018005" version="502" comment="fetchmail is earlier than 0:6.2.5-6.el4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070018005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070019002" version="503" comment="gtk2 is earlier than 0:2.4.13-22" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070019002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070019003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070019003" version="503" comment="gtk2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070019002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070019004" version="503" comment="gtk2-devel is earlier than 0:2.4.13-22" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070019003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070019003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070019005" version="503" comment="gtk2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070019003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070022002" version="502" comment="squirrelmail is earlier than 0:1.4.8-4.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070022003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070022003" version="502" comment="squirrelmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070022005" version="502" comment="squirrelmail is earlier than 0:1.4.8-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070022005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033002" version="502" comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033004" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033006" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033009" version="502" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033010" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033011" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070033013" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070033005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044002" version="502" comment="bind is earlier than 20:9.2.4-20.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044003" version="502" comment="bind is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044004" version="502" comment="bind-devel is earlier than 20:9.2.4-20.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044005" version="502" comment="bind-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044006" version="502" comment="bind-libs is earlier than 20:9.2.4-20.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044007" version="502" comment="bind-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044008" version="502" comment="bind-chroot is earlier than 20:9.2.4-20.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044009" version="502" comment="bind-chroot is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044010" version="502" comment="bind-utils is earlier than 20:9.2.4-20.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044011" version="502" comment="bind-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044013" version="502" comment="bind is earlier than 20:9.2.4-24.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044014" version="502" comment="bind-chroot is earlier than 20:9.2.4-24.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044015" version="502" comment="bind-devel is earlier than 20:9.2.4-24.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044016" version="502" comment="bind-utils is earlier than 20:9.2.4-24.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070044017" version="502" comment="bind-libs is earlier than 20:9.2.4-24.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070044005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055001" version="503" comment="Red Hat Enterprise Linux 5 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055002" version="503" comment="libwpd is earlier than 0:0.8.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055003" version="503" comment="libwpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055004" version="503" comment="libwpd-devel is earlier than 0:0.8.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055005" version="503" comment="libwpd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055006" version="503" comment="libwpd-tools is earlier than 0:0.8.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070055007" version="503" comment="libwpd-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057002" version="503" comment="bind is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057003" version="503" comment="bind is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057004" version="503" comment="bind-chroot is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057005" version="503" comment="bind-chroot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057006" version="503" comment="bind-devel is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057007" version="503" comment="bind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057008" version="503" comment="bind-sdb is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057009" version="503" comment="bind-sdb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057010" version="503" comment="bind-utils is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057011" version="503" comment="bind-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057012" version="503" comment="caching-nameserver is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057013" version="503" comment="caching-nameserver is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057014" version="503" comment="bind-libbind-devel is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057015" version="503" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057016" version="503" comment="bind-libs is earlier than 30:9.3.3-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070057003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070057017" version="503" comment="bind-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060002" version="502" comment="samba is earlier than 0:3.0.9-1.3E.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060003" version="502" comment="samba is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060004" version="502" comment="samba-swat is earlier than 0:3.0.9-1.3E.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060005" version="502" comment="samba-swat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060006" version="502" comment="samba-client is earlier than 0:3.0.9-1.3E.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060007" version="502" comment="samba-client is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060008" version="502" comment="samba-common is earlier than 0:3.0.9-1.3E.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060009" version="502" comment="samba-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060011" version="502" comment="samba is earlier than 0:3.0.10-1.4E.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060012" version="502" comment="samba-common is earlier than 0:3.0.10-1.4E.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060013" version="502" comment="samba-client is earlier than 0:3.0.10-1.4E.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070060014" version="502" comment="samba-swat is earlier than 0:3.0.10-1.4E.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070060005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061002" version="503" comment="samba is earlier than 0:3.0.23c-2.el5.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061003" version="503" comment="samba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061004" version="503" comment="samba-common is earlier than 0:3.0.23c-2.el5.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061005" version="503" comment="samba-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061006" version="503" comment="samba-swat is earlier than 0:3.0.23c-2.el5.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061007" version="503" comment="samba-swat is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061008" version="503" comment="samba-client is earlier than 0:3.0.23c-2.el5.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070061009" version="503" comment="samba-client is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064002" version="502" comment="rh-postgresql is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064003" version="502" comment="rh-postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064004" version="502" comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064005" version="502" comment="rh-postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064006" version="502" comment="rh-postgresql-test is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064007" version="502" comment="rh-postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064008" version="502" comment="rh-postgresql-docs is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064009" version="502" comment="rh-postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064010" version="502" comment="rh-postgresql-libs is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064011" version="502" comment="rh-postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064012" version="502" comment="rh-postgresql-devel is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064013" version="502" comment="rh-postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064014" version="502" comment="rh-postgresql-pl is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064015" version="502" comment="rh-postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064016" version="502" comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064017" version="502" comment="rh-postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064018" version="502" comment="rh-postgresql-python is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064019" version="502" comment="rh-postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064020" version="502" comment="rh-postgresql-server is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064021" version="502" comment="rh-postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064022" version="502" comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064023" version="502" comment="rh-postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064025" version="502" comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064026" version="502" comment="postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064027" version="502" comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064028" version="502" comment="postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064029" version="502" comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064030" version="502" comment="postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064031" version="502" comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064032" version="502" comment="postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064033" version="502" comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064034" version="502" comment="postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064035" version="502" comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064036" version="502" comment="postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064037" version="502" comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064038" version="502" comment="postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064039" version="502" comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064040" version="502" comment="postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064041" version="502" comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064042" version="502" comment="postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064043" version="502" comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064044" version="502" comment="postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064045" version="502" comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070064005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070064046" version="502" comment="postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070065002" version="503" comment="bluez-utils is earlier than 0:2.10-2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070065002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070065003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070065003" version="503" comment="bluez-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070065002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070065004" version="503" comment="bluez-utils-cups is earlier than 0:2.10-2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070065003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070065003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070065005" version="503" comment="bluez-utils-cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070065003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066002" version="502" comment="wireshark is earlier than 0:0.99.5-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066003" version="502" comment="wireshark is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066004" version="502" comment="wireshark-gnome is earlier than 0:0.99.5-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066005" version="502" comment="wireshark-gnome is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066007" version="502" comment="wireshark is earlier than 0:0.99.5-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066008" version="502" comment="wireshark is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066009" version="502" comment="wireshark-gnome is earlier than 0:0.99.5-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066010" version="502" comment="wireshark-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066012" version="502" comment="wireshark is earlier than 0:0.99.5-EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070066013" version="502" comment="wireshark-gnome is earlier than 0:0.99.5-EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070066008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068002" version="503" comment="postgresql is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068003" version="503" comment="postgresql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068004" version="503" comment="postgresql-docs is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068005" version="503" comment="postgresql-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068006" version="503" comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068007" version="503" comment="postgresql-tcl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068008" version="503" comment="postgresql-devel is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068009" version="503" comment="postgresql-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068010" version="503" comment="postgresql-libs is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068011" version="503" comment="postgresql-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068012" version="503" comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068013" version="503" comment="postgresql-contrib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068014" version="503" comment="postgresql-python is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068015" version="503" comment="postgresql-python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068016" version="503" comment="postgresql-pl is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068017" version="503" comment="postgresql-pl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068018" version="503" comment="postgresql-server is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068019" version="503" comment="postgresql-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068020" version="503" comment="postgresql-test is earlier than 0:8.1.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070068003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070068021" version="503" comment="postgresql-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069002" version="502" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069003" version="502" comment="openoffice.org is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069004" version="502" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069005" version="502" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069006" version="502" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069007" version="502" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069008" version="502" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069009" version="502" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069010" version="502" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069011" version="502" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069012" version="502" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069013" version="502" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069014" version="502" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069015" version="502" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069016" version="502" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069017" version="502" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069018" version="502" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069019" version="502" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069020" version="502" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069021" version="502" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069022" version="502" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069023" version="502" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069024" version="502" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069025" version="502" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069026" version="502" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069027" version="502" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069028" version="502" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069029" version="502" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069030" version="502" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069031" version="502" comment="openoffice.org-base is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069032" version="502" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069033" version="502" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069034" version="502" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069035" version="502" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069036" version="502" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069037" version="502" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069038" version="502" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069039" version="502" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069040" version="502" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069041" version="502" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069042" version="502" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069043" version="502" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069044" version="502" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069045" version="502" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069046" version="502" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069047" version="502" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069048" version="502" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069049" version="502" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069050" version="502" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069051" version="502" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069052" version="502" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069053" version="502" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069054" version="502" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069055" version="502" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069056" version="502" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069057" version="502" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069058" version="502" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069059" version="502" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069060" version="502" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069061" version="502" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069062" version="502" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069063" version="502" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069064" version="502" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069065" version="502" comment="openoffice.org-math is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069066" version="502" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069067" version="502" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069068" version="502" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069069" version="502" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069070" version="502" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069071" version="502" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069072" version="502" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069073" version="502" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069074" version="502" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069075" version="502" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069076" version="502" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069077" version="502" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069078" version="502" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069079" version="502" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069080" version="502" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069081" version="502" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069082" version="502" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069083" version="502" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069084" version="502" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069085" version="502" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069086" version="502" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069087" version="502" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069088" version="502" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069089" version="502" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069090" version="502" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069091" version="502" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069092" version="502" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069093" version="502" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069094" version="502" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069095" version="502" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069096" version="502" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069097" version="502" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069098" version="502" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069099" version="502" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069100" version="502" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069101" version="502" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069102" version="502" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069103" version="502" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069104" version="502" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069105" version="502" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069106" version="502" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069107" version="502" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069108" version="502" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069109" version="502" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069110" version="502" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069111" version="502" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069112" version="502" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069113" version="502" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069114" version="502" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069115" version="502" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069116" version="502" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069117" version="502" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069118" version="502" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069119" version="502" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069120" version="502" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069121" version="502" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069122" version="502" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069123" version="502" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069124" version="502" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069125" version="502" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069126" version="502" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069127" version="502" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069128" version="502" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069129" version="502" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069130" version="502" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069131" version="502" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069132" version="502" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069133" version="502" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069134" version="502" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069135" version="502" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069136" version="502" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069137" version="502" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069138" version="502" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069139" version="502" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069140" version="502" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069141" version="502" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069142" version="502" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069143" version="502" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069144" version="502" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069145" version="502" comment="openoffice.org-core is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069146" version="502" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069147" version="502" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069148" version="502" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070069003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070069149" version="502" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070074002" version="502" comment="spamassassin is earlier than 0:3.1.8-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070074003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070074003" version="502" comment="spamassassin is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070075002" version="503" comment="spamassassin is earlier than 0:3.1.8-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070075003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070075003" version="503" comment="spamassassin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076002" version="502" comment="php is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076003" version="502" comment="php is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076004" version="502" comment="php-pgsql is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076005" version="502" comment="php-pgsql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076006" version="502" comment="php-odbc is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076007" version="502" comment="php-odbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076008" version="502" comment="php-devel is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076009" version="502" comment="php-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076010" version="502" comment="php-mysql is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076011" version="502" comment="php-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076012" version="502" comment="php-ldap is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076013" version="502" comment="php-ldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076014" version="502" comment="php-imap is earlier than 0:4.3.2-39.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076015" version="502" comment="php-imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076017" version="502" comment="php is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076018" version="502" comment="php-ldap is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076019" version="502" comment="php-pear is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076020" version="502" comment="php-pear is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076021" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076022" version="502" comment="php-mbstring is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076023" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076024" version="502" comment="php-xmlrpc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076025" version="502" comment="php-snmp is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076026" version="502" comment="php-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076027" version="502" comment="php-domxml is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076028" version="502" comment="php-domxml is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076029" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076030" version="502" comment="php-ncurses is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076031" version="502" comment="php-imap is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076032" version="502" comment="php-odbc is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076033" version="502" comment="php-devel is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076034" version="502" comment="php-mysql is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076035" version="502" comment="php-gd is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076036" version="502" comment="php-gd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070076037" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.22.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070076005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077002" version="504" comment="seamonkey is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077003" version="504" comment="seamonkey is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077004" version="504" comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077005" version="504" comment="seamonkey-mail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077006" version="504" comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077007" version="504" comment="seamonkey-nss-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077008" version="504" comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077009" version="504" comment="seamonkey-nspr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077010" version="504" comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077011" version="504" comment="seamonkey-js-debugger is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077012" version="504" comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077013" version="504" comment="seamonkey-nss is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077014" version="504" comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077015" version="504" comment="seamonkey-chat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077016" version="504" comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077017" version="504" comment="seamonkey-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077018" version="504" comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077019" version="504" comment="seamonkey-dom-inspector is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077020" version="504" comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077021" version="504" comment="seamonkey-nspr-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077023" version="504" comment="devhelp is earlier than 0:0.10-0.7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077024" version="504" comment="devhelp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077025" version="504" comment="devhelp-devel is earlier than 0:0.10-0.7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077026" version="504" comment="devhelp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077027" version="504" comment="seamonkey is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077028" version="504" comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077029" version="504" comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077030" version="504" comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077031" version="504" comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077032" version="504" comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077033" version="504" comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077034" version="504" comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077035" version="504" comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070077036" version="504" comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070077006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070078002" version="503" comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070078003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070078003" version="503" comment="thunderbird is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070079002" version="502" comment="firefox is earlier than 0:1.5.0.10-0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070078003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070079003" version="502" comment="firefox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082002" version="503" comment="php is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082003" version="503" comment="php is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082004" version="503" comment="php-xmlrpc is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082005" version="503" comment="php-xmlrpc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082006" version="503" comment="php-dba is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082007" version="503" comment="php-dba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082008" version="503" comment="php-common is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082009" version="503" comment="php-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082010" version="503" comment="php-bcmath is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082011" version="503" comment="php-bcmath is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082012" version="503" comment="php-ncurses is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082013" version="503" comment="php-ncurses is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082014" version="503" comment="php-soap is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082015" version="503" comment="php-soap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082016" version="503" comment="php-snmp is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082017" version="503" comment="php-snmp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082018" version="503" comment="php-cli is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082019" version="503" comment="php-cli is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082020" version="503" comment="php-devel is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082021" version="503" comment="php-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082022" version="503" comment="php-pgsql is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082023" version="503" comment="php-pgsql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082024" version="503" comment="php-mysql is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082025" version="503" comment="php-mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082026" version="503" comment="php-pdo is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082027" version="503" comment="php-pdo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082028" version="503" comment="php-ldap is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082029" version="503" comment="php-ldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082030" version="503" comment="php-imap is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082031" version="503" comment="php-imap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082032" version="503" comment="php-mbstring is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082033" version="503" comment="php-mbstring is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082034" version="503" comment="php-gd is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082035" version="503" comment="php-gd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082036" version="503" comment="php-odbc is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082037" version="503" comment="php-odbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082038" version="503" comment="php-xml is earlier than 0:5.1.6-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070082039" version="503" comment="php-xml is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085002" version="502" comment="kernel is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085004" version="502" comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085006" version="502" comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085008" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085010" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085012" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085014" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085016" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070085018" version="502" comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070085003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070086002" version="502" comment="gnomemeeting is earlier than 0:0.96.0-5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070086002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070086003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070086003" version="502" comment="gnomemeeting is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070086002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070086005" version="502" comment="gnomemeeting is earlier than 0:1.0.2-9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070086002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070086005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070087002" version="503" comment="ekiga is earlier than 0:2.0.2-7.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070087002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070087003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070087003" version="503" comment="ekiga is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070087002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095002" version="502" comment="krb5 is earlier than 0:1.5-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095003" version="502" comment="krb5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095004" version="502" comment="krb5-workstation is earlier than 0:1.5-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095005" version="502" comment="krb5-workstation is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095006" version="502" comment="krb5-libs is earlier than 0:1.5-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095007" version="502" comment="krb5-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095008" version="502" comment="krb5-devel is earlier than 0:1.5-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095009" version="502" comment="krb5-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095010" version="502" comment="krb5-server is earlier than 0:1.5-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095011" version="502" comment="krb5-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095013" version="502" comment="krb5 is earlier than 0:1.2.7-61" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095014" version="502" comment="krb5 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095015" version="502" comment="krb5-libs is earlier than 0:1.2.7-61" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095016" version="502" comment="krb5-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095017" version="502" comment="krb5-workstation is earlier than 0:1.2.7-61" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095018" version="502" comment="krb5-workstation is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095019" version="502" comment="krb5-devel is earlier than 0:1.2.7-61" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095020" version="502" comment="krb5-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095021" version="502" comment="krb5-server is earlier than 0:1.2.7-61" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095022" version="502" comment="krb5-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095024" version="502" comment="krb5 is earlier than 0:1.3.4-46" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095025" version="502" comment="krb5-devel is earlier than 0:1.3.4-46" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095026" version="502" comment="krb5-libs is earlier than 0:1.3.4-46" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095027" version="502" comment="krb5-workstation is earlier than 0:1.3.4-46" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070095028" version="502" comment="krb5-server is earlier than 0:1.3.4-46" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070095008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097002" version="503" comment="devhelp is earlier than 0:0.12-10.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070097003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097003" version="503" comment="devhelp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097004" version="503" comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070097003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097005" version="503" comment="devhelp-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097006" version="503" comment="yelp is earlier than 0:2.16.0-14.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070097004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097007" version="503" comment="yelp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097008" version="503" comment="firefox is earlier than 0:1.5.0.10-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070097005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097009" version="503" comment="firefox is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097010" version="503" comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070097005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070097011" version="503" comment="firefox-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099002" version="503" comment="kernel is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099003" version="503" comment="kernel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099004" version="503" comment="kernel-headers is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099005" version="503" comment="kernel-headers is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099006" version="503" comment="kernel-xen is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099007" version="503" comment="kernel-xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099008" version="503" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099009" version="503" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099010" version="503" comment="kernel-devel is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099011" version="503" comment="kernel-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099012" version="503" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099013" version="503" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099014" version="503" comment="kernel-kdump is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099015" version="503" comment="kernel-kdump is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099016" version="503" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099017" version="503" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099018" version="503" comment="kernel-PAE is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099019" version="503" comment="kernel-PAE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099020" version="503" comment="kernel-doc is earlier than 0:2.6.18-8.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070099003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070099021" version="503" comment="kernel-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070106002" version="502" comment="gnupg is earlier than 0:1.2.1-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070106003" version="502" comment="gnupg is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070106005" version="502" comment="gnupg is earlier than 0:1.2.6-9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070106005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070107002" version="503" comment="gnupg is earlier than 0:1.4.5-13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070107003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070107003" version="503" comment="gnupg is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070106002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070108002" version="503" comment="thunderbird is earlier than 0:1.5.0.10-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070108003" version="503" comment="thunderbird is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114002" version="503" comment="xen is earlier than 0:3.0.3-25.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070114003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114003" version="503" comment="xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114004" version="503" comment="xen-libs is earlier than 0:3.0.3-25.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070114003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114005" version="503" comment="xen-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114006" version="503" comment="xen-devel is earlier than 0:3.0.3-25.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070114003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070114007" version="503" comment="xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123002" version="502" comment="cups is earlier than 1:1.2.4-11.5.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123003" version="502" comment="cups is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123004" version="502" comment="cups-lpd is earlier than 1:1.2.4-11.5.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123005" version="502" comment="cups-lpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123006" version="502" comment="cups-libs is earlier than 1:1.2.4-11.5.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123007" version="502" comment="cups-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123008" version="502" comment="cups-devel is earlier than 1:1.2.4-11.5.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123009" version="502" comment="cups-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123011" version="502" comment="cups is earlier than 1:1.1.17-13.3.42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123012" version="502" comment="cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123013" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123014" version="502" comment="cups-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123015" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.42" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123016" version="502" comment="cups-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123018" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.18" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123019" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.18" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070123020" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.18" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070123008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070124002" version="502" comment="file is earlier than 0:4.17-9.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070124004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070124003" version="502" comment="file is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070124005" version="502" comment="file is earlier than 0:4.10-3.EL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070124006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070124006" version="502" comment="file is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125002" version="502" comment="XFree86 is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125004" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125006" version="502" comment="XFree86-libs-data is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125008" version="502" comment="XFree86-sdk is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125010" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125012" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125014" version="502" comment="XFree86-twm is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125016" version="502" comment="XFree86-xfs is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125018" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125020" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125022" version="502" comment="XFree86-doc is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125024" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125026" version="502" comment="XFree86-Xvfb is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125028" version="502" comment="XFree86-font-utils is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125030" version="502" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125032" version="502" comment="XFree86-xdm is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125034" version="502" comment="XFree86-base-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125036" version="502" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125038" version="502" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125040" version="502" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125042" version="502" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125044" version="502" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125046" version="502" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125048" version="502" comment="XFree86-Xnest is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125050" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125052" version="502" comment="XFree86-xauth is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125054" version="502" comment="XFree86-devel is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125056" version="502" comment="XFree86-tools is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125058" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070125060" version="502" comment="XFree86-libs is earlier than 0:4.3.0-120.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070002029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126002" version="502" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126004" version="502" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126006" version="502" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126008" version="502" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126010" version="502" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126012" version="502" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126014" version="502" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126016" version="502" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126018" version="502" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126020" version="502" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126022" version="502" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126024" version="502" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126026" version="502" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126028" version="502" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126030" version="502" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126032" version="502" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126034" version="502" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070126036" version="502" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127002" version="502" comment="xorg-x11-server is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127003" version="502" comment="xorg-x11-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127004" version="502" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127005" version="502" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127006" version="502" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127007" version="502" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127008" version="502" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127009" version="502" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127010" version="502" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127011" version="502" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127012" version="502" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127013" version="502" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127014" version="502" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.13.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070127003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070127015" version="502" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070127008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070131002" version="502" comment="squid is earlier than 7:2.6.STABLE6-4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070131002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070131003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070131003" version="502" comment="squid is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070131002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070132002" version="502" comment="libXfont is earlier than 0:1.2.2-1.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070132002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070132003" version="502" comment="libXfont is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070132002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070132004" version="502" comment="libXfont-devel is earlier than 0:1.2.2-1.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070132003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070132005" version="502" comment="libXfont-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070132003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150002" version="502" comment="freetype is earlier than 0:2.2.1-17.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150003" version="502" comment="freetype is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150004" version="502" comment="freetype-demos is earlier than 0:2.2.1-17.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150005" version="502" comment="freetype-demos is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150006" version="502" comment="freetype-devel is earlier than 0:2.2.1-17.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150007" version="502" comment="freetype-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150009" version="502" comment="freetype is earlier than 0:2.1.4-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150010" version="502" comment="freetype is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150011" version="502" comment="freetype-demos is earlier than 0:2.1.4-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150012" version="502" comment="freetype-demos is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150013" version="502" comment="freetype-utils is earlier than 0:2.1.4-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150014" version="502" comment="freetype-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150015" version="502" comment="freetype-devel is earlier than 0:2.1.4-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150016" version="502" comment="freetype-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150018" version="502" comment="freetype is earlier than 0:2.1.9-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150019" version="502" comment="freetype-devel is earlier than 0:2.1.9-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150020" version="502" comment="freetype-utils is earlier than 0:2.1.9-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070150021" version="502" comment="freetype-demos is earlier than 0:2.1.9-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070150008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152002" version="502" comment="mysql is earlier than 0:4.1.20-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152003" version="502" comment="mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152004" version="502" comment="mysql-devel is earlier than 0:4.1.20-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152005" version="502" comment="mysql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152006" version="502" comment="mysql-bench is earlier than 0:4.1.20-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152007" version="502" comment="mysql-bench is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152008" version="502" comment="mysql-server is earlier than 0:4.1.20-2.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070152003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070152009" version="502" comment="mysql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070152005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153002" version="502" comment="php is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153004" version="502" comment="php-xml is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153006" version="502" comment="php-common is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153008" version="502" comment="php-gd is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153010" version="502" comment="php-snmp is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153012" version="502" comment="php-bcmath is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153014" version="502" comment="php-soap is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153016" version="502" comment="php-xmlrpc is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153018" version="502" comment="php-odbc is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153020" version="502" comment="php-ldap is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153022" version="502" comment="php-cli is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153024" version="502" comment="php-devel is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153026" version="502" comment="php-imap is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153028" version="502" comment="php-ncurses is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153030" version="502" comment="php-mysql is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153032" version="502" comment="php-pdo is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153034" version="502" comment="php-pgsql is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153036" version="502" comment="php-mbstring is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070153038" version="502" comment="php-dba is earlier than 0:5.1.6-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155002" version="502" comment="php is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155004" version="502" comment="php-devel is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155006" version="502" comment="php-imap is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155008" version="502" comment="php-ldap is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155010" version="502" comment="php-odbc is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155012" version="502" comment="php-mysql is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155014" version="502" comment="php-pgsql is earlier than 0:4.3.2-40.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155017" version="502" comment="php is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155018" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155020" version="502" comment="php-ldap is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155021" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155023" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155025" version="502" comment="php-imap is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155026" version="502" comment="php-domxml is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155028" version="502" comment="php-odbc is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155029" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155030" version="502" comment="php-devel is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155031" version="502" comment="php-snmp is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155033" version="502" comment="php-mysql is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155034" version="502" comment="php-pear is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070155036" version="502" comment="php-gd is earlier than 0:4.3.9-3.22.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070155005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157002" version="502" comment="libX11 is earlier than 0:1.0.3-8.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157003" version="502" comment="libX11 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157004" version="502" comment="libX11-devel is earlier than 0:1.0.3-8.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157005" version="502" comment="libX11-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157006" version="502" comment="xorg-x11-apps is earlier than 0:7.1-4.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070157004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070157007" version="502" comment="xorg-x11-apps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070158002" version="502" comment="evolution is earlier than 0:2.8.0-33.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070158003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070158003" version="502" comment="evolution is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070158004" version="502" comment="evolution-devel is earlier than 0:2.8.0-33.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070158003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070158005" version="502" comment="evolution-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166002" version="502" comment="java-1.4.2-ibm is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166003" version="502" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166004" version="502" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166005" version="502" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166006" version="502" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166007" version="502" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166008" version="502" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166009" version="502" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166010" version="502" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166011" version="502" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166012" version="502" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166013" version="502" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166014" version="502" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.8-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070166004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070166015" version="502" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167002" version="502" comment="java-1.5.0-ibm is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167003" version="502" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167004" version="502" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167005" version="502" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167006" version="502" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167007" version="502" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167008" version="502" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167009" version="502" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167010" version="502" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167011" version="502" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167012" version="502" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167013" version="502" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167014" version="502" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.4-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070167004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070167015" version="502" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169002" version="502" comment="kernel is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169004" version="502" comment="kernel-headers is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169006" version="502" comment="kernel-devel is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169008" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169010" version="502" comment="kernel-xen is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169012" version="502" comment="kernel-kdump is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169014" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169016" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169018" version="502" comment="kernel-PAE is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070169020" version="502" comment="kernel-doc is earlier than 0:2.6.18-8.1.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070169003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070203002" version="503" comment="unzip is earlier than 0:5.51-9.EL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070203002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070203003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070203003" version="503" comment="unzip is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070203002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208002" version="503" comment="w3c-libwww is earlier than 0:5.4.0-10.1.RHEL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208003" version="503" comment="w3c-libwww is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208004" version="503" comment="w3c-libwww-devel is earlier than 0:5.4.0-10.1.RHEL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208005" version="503" comment="w3c-libwww-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208006" version="503" comment="w3c-libwww-apps is earlier than 0:5.4.0-10.1.RHEL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070208007" version="503" comment="w3c-libwww-apps is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070208004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220002" version="503" comment="gcc is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220003" version="503" comment="gcc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220004" version="503" comment="gcc-java is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220005" version="503" comment="gcc-java is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220006" version="503" comment="gcc-objc is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220007" version="503" comment="gcc-objc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220008" version="503" comment="libstdc++-devel is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220009" version="503" comment="libstdc++-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220010" version="503" comment="gcc-ppc32 is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220011" version="503" comment="gcc-ppc32 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220012" version="503" comment="libstdc++ is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220013" version="503" comment="libstdc++ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220014" version="503" comment="gcc-c++ is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220015" version="503" comment="gcc-c++ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220016" version="503" comment="libgcc is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220017" version="503" comment="libgcc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220018" version="503" comment="libobjc is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220019" version="503" comment="libobjc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220020" version="503" comment="libgnat is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220021" version="503" comment="libgnat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220022" version="503" comment="cpp is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220023" version="503" comment="cpp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220024" version="503" comment="libgcj-devel is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220025" version="503" comment="libgcj-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220026" version="503" comment="gcc-gnat is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220027" version="503" comment="gcc-gnat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220028" version="503" comment="gcc-c++-ppc32 is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220029" version="503" comment="gcc-c++-ppc32 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220030" version="503" comment="gcc-g77 is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220031" version="503" comment="gcc-g77 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220032" version="503" comment="libgcj is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220033" version="503" comment="libgcj is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220034" version="503" comment="libf2c is earlier than 0:3.4.6-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070220003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070220035" version="503" comment="libf2c is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070229002" version="503" comment="gdb is earlier than 0:6.3.0.0-1.143.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070229002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070229003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070229003" version="503" comment="gdb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070229002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070235002" version="503" comment="util-linux is earlier than 0:2.12a-16.EL4.25" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070235003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070235003" version="503" comment="util-linux is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070244002" version="503" comment="busybox is earlier than 0:1.00.rc1-7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070244002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070244003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070244003" version="503" comment="busybox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070244002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070244004" version="503" comment="busybox-anaconda is earlier than 0:1.00.rc1-7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070244003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070244003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070244005" version="503" comment="busybox-anaconda is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070244003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070245002" version="503" comment="cpio is earlier than 0:2.5-13.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070245002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070245003" version="503" comment="cpio is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070245002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252002" version="503" comment="sendmail is earlier than 0:8.13.1-3.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070252003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252003" version="503" comment="sendmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252004" version="503" comment="sendmail-devel is earlier than 0:8.13.1-3.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070252003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252005" version="503" comment="sendmail-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252006" version="503" comment="sendmail-doc is earlier than 0:8.13.1-3.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070252003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252007" version="503" comment="sendmail-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252008" version="503" comment="sendmail-cf is earlier than 0:8.13.1-3.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070252003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070252009" version="503" comment="sendmail-cf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070252005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257002" version="503" comment="openssh is earlier than 0:3.9p1-8.RHEL4.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257003" version="503" comment="openssh is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257004" version="503" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257005" version="503" comment="openssh-clients is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257006" version="503" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257007" version="503" comment="openssh-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257008" version="503" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257009" version="503" comment="openssh-askpass-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257010" version="503" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070257011" version="503" comment="openssh-askpass is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070276002" version="503" comment="shadow-utils is earlier than 2:4.0.3-61.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070276002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070276003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070276003" version="503" comment="shadow-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070276002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070286002" version="503" comment="gdm is earlier than 1:2.6.0.5-7.rhel4.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070286002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070286003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070286003" version="503" comment="gdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070286002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310002" version="503" comment="openldap is earlier than 0:2.2.13-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310003" version="503" comment="openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310004" version="503" comment="openldap-servers is earlier than 0:2.2.13-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310005" version="503" comment="openldap-servers is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310006" version="503" comment="openldap-clients is earlier than 0:2.2.13-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310007" version="503" comment="openldap-clients is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310008" version="503" comment="openldap-devel is earlier than 0:2.2.13-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310009" version="503" comment="openldap-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310010" version="503" comment="openldap-servers-sql is earlier than 0:2.2.13-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310011" version="503" comment="openldap-servers-sql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310012" version="503" comment="compat-openldap is earlier than 0:2.1.30-7.4E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070310004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070310013" version="503" comment="compat-openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070322002" version="503" comment="xscreensaver is earlier than 1:4.10-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070322002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070322003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070322003" version="503" comment="xscreensaver is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070322002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070322005" version="503" comment="xscreensaver is earlier than 1:4.18-5.rhel4.14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070322002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070322005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070323002" version="502" comment="xen is earlier than 0:3.0.3-25.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070323004" version="502" comment="xen-libs is earlier than 0:3.0.3-25.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070323006" version="502" comment="xen-devel is earlier than 0:3.0.3-25.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070114004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070323003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327002" version="502" comment="redhat-rpm-config is earlier than 0:8.0.45-17.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327003" version="502" comment="redhat-rpm-config is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327004" version="502" comment="tomcat5 is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327005" version="502" comment="tomcat5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327006" version="502" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327007" version="502" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327008" version="502" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327009" version="502" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327010" version="502" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327011" version="502" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327012" version="502" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327013" version="502" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327014" version="502" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327015" version="502" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327016" version="502" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327017" version="502" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327018" version="502" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327019" version="502" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327020" version="502" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327021" version="502" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327022" version="502" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327023" version="502" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327024" version="502" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327025" version="502" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327026" version="502" comment="jakarta-commons-modeler is earlier than 0:1.1-8jpp.1.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327027" version="502" comment="jakarta-commons-modeler is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327028" version="502" comment="jakarta-commons-modeler-javadoc is earlier than 0:1.1-8jpp.1.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070327005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070327029" version="502" comment="jakarta-commons-modeler-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336002" version="503" comment="postgresql is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336004" version="503" comment="postgresql-libs is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336006" version="503" comment="postgresql-contrib is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336008" version="503" comment="postgresql-python is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336010" version="503" comment="postgresql-test is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336012" version="503" comment="postgresql-tcl is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336014" version="503" comment="postgresql-docs is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336016" version="503" comment="postgresql-pl is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336018" version="503" comment="postgresql-devel is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336020" version="503" comment="postgresql-server is earlier than 0:8.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336023" version="503" comment="rh-postgresql is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336025" version="503" comment="rh-postgresql-jdbc is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336027" version="503" comment="rh-postgresql-server is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336029" version="503" comment="rh-postgresql-pl is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336031" version="503" comment="rh-postgresql-docs is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336033" version="503" comment="rh-postgresql-libs is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336035" version="503" comment="rh-postgresql-devel is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336037" version="503" comment="rh-postgresql-tcl is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336039" version="503" comment="rh-postgresql-python is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336041" version="503" comment="rh-postgresql-contrib is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336043" version="503" comment="rh-postgresql-test is earlier than 0:7.3.19-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336046" version="503" comment="postgresql is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336048" version="503" comment="postgresql-devel is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336050" version="503" comment="postgresql-contrib is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336052" version="503" comment="postgresql-jdbc is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336054" version="503" comment="postgresql-python is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336056" version="503" comment="postgresql-test is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336058" version="503" comment="postgresql-docs is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336060" version="503" comment="postgresql-server is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336062" version="503" comment="postgresql-libs is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336064" version="503" comment="postgresql-tcl is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070336066" version="503" comment="postgresql-pl is earlier than 0:7.4.17-1.RHEL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070064014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070336008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338002" version="503" comment="freeradius is earlier than 0:1.1.3-1.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338003" version="503" comment="freeradius is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338004" version="503" comment="freeradius-mysql is earlier than 0:1.1.3-1.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338005" version="503" comment="freeradius-mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338006" version="503" comment="freeradius-unixODBC is earlier than 0:1.1.3-1.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338007" version="503" comment="freeradius-unixODBC is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338008" version="503" comment="freeradius-postgresql is earlier than 0:1.1.3-1.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338009" version="503" comment="freeradius-postgresql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338011" version="503" comment="freeradius is earlier than 0:1.0.1-2.RHEL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338012" version="503" comment="freeradius is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338013" version="503" comment="freeradius-unixODBC is earlier than 0:1.0.1-2.RHEL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338014" version="503" comment="freeradius-unixODBC is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338015" version="503" comment="freeradius-postgresql is earlier than 0:1.0.1-2.RHEL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338016" version="503" comment="freeradius-postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338017" version="503" comment="freeradius-mysql is earlier than 0:1.0.1-2.RHEL3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338018" version="503" comment="freeradius-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338020" version="503" comment="freeradius is earlier than 0:1.0.1-3.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338021" version="503" comment="freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338022" version="503" comment="freeradius-mysql is earlier than 0:1.0.1-3.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070338023" version="503" comment="freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070338004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070338008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070342002" version="502" comment="ipsec-tools is earlier than 0:0.6.5-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070342002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070342003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070342003" version="502" comment="ipsec-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070342002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343002" version="503" comment="gimp is earlier than 2:2.2.13-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343003" version="503" comment="gimp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343004" version="503" comment="gimp-devel is earlier than 2:2.2.13-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343005" version="503" comment="gimp-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343006" version="503" comment="gimp-libs is earlier than 2:2.2.13-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343007" version="503" comment="gimp-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343009" version="503" comment="gimp is earlier than 1:1.2.3-20.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343010" version="503" comment="gimp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343011" version="503" comment="gimp-perl is earlier than 1:1.2.3-20.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343012" version="503" comment="gimp-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343013" version="503" comment="gimp-devel is earlier than 1:1.2.3-20.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343014" version="503" comment="gimp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343016" version="503" comment="gimp is earlier than 1:2.0.5-6.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070343017" version="503" comment="gimp-devel is earlier than 1:2.0.5-6.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070343008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070344002" version="502" comment="evolution-data-server is earlier than 0:1.8.0-15.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070344003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070344003" version="502" comment="evolution-data-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070344004" version="502" comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070344003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070344005" version="502" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070345002" version="503" comment="vixie-cron is earlier than 4:4.1-70.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070345004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070345003" version="503" comment="vixie-cron is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070345005" version="503" comment="vixie-cron is earlier than 0:4.1-19.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070345006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070345006" version="503" comment="vixie-cron is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070345008" version="503" comment="vixie-cron is earlier than 4:4.1-47.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070345008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346002" version="502" comment="vim is earlier than 2:7.0.109-3.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346003" version="502" comment="vim is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346004" version="502" comment="vim-minimal is earlier than 2:7.0.109-3.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346005" version="502" comment="vim-minimal is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346006" version="502" comment="vim-enhanced is earlier than 2:7.0.109-3.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346007" version="502" comment="vim-enhanced is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346008" version="502" comment="vim-X11 is earlier than 2:7.0.109-3.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346009" version="502" comment="vim-X11 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346010" version="502" comment="vim-common is earlier than 2:7.0.109-3.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070346003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070346011" version="502" comment="vim-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070346006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347002" version="502" comment="kernel is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347004" version="502" comment="kernel-headers is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347006" version="502" comment="kernel-devel is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347008" version="502" comment="kernel-xen is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347010" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347012" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347014" version="502" comment="kernel-kdump is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347016" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347018" version="502" comment="kernel-PAE is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070347020" version="502" comment="kernel-doc is earlier than 0:2.6.18-8.1.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070347003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348002" version="502" comment="php is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348004" version="502" comment="php-ncurses is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348006" version="502" comment="php-snmp is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348008" version="502" comment="php-ldap is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348010" version="502" comment="php-dba is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348012" version="502" comment="php-imap is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348014" version="502" comment="php-devel is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348016" version="502" comment="php-soap is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348018" version="502" comment="php-xml is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348020" version="502" comment="php-pgsql is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348022" version="502" comment="php-bcmath is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348024" version="502" comment="php-mbstring is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348026" version="502" comment="php-pdo is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348028" version="502" comment="php-cli is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348030" version="502" comment="php-odbc is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348032" version="502" comment="php-xmlrpc is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348034" version="502" comment="php-gd is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348036" version="502" comment="php-mysql is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070348038" version="502" comment="php-common is earlier than 0:5.1.6-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070082005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070348003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349002" version="503" comment="php is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349004" version="503" comment="php-mysql is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349006" version="503" comment="php-devel is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349008" version="503" comment="php-ncurses is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349010" version="503" comment="php-mbstring is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349012" version="503" comment="php-domxml is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349014" version="503" comment="php-snmp is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349016" version="503" comment="php-odbc is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349018" version="503" comment="php-imap is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349020" version="503" comment="php-pgsql is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349022" version="503" comment="php-pear is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349024" version="503" comment="php-ldap is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349026" version="503" comment="php-gd is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070349028" version="503" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070076011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070349003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353002" version="504" comment="evolution is earlier than 0:1.4.5-20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070353003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353003" version="504" comment="evolution is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353004" version="504" comment="evolution-devel is earlier than 0:1.4.5-20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070353003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353005" version="504" comment="evolution-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353007" version="504" comment="evolution is earlier than 0:2.0.2-35.0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070353005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070353008" version="504" comment="evolution-devel is earlier than 0:2.0.2-35.0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070353005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354002" version="503" comment="samba is earlier than 0:3.0.23c-2.el5.2.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354004" version="503" comment="samba-swat is earlier than 0:3.0.23c-2.el5.2.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354006" version="503" comment="samba-common is earlier than 0:3.0.23c-2.el5.2.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354008" version="503" comment="samba-client is earlier than 0:3.0.23c-2.el5.2.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354011" version="503" comment="samba is earlier than 0:3.0.9-1.3E.13.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354013" version="503" comment="samba-client is earlier than 0:3.0.9-1.3E.13.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354015" version="503" comment="samba-common is earlier than 0:3.0.9-1.3E.13.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354017" version="503" comment="samba-swat is earlier than 0:3.0.9-1.3E.13.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354020" version="503" comment="samba is earlier than 0:3.0.10-1.4E.12.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354021" version="503" comment="samba-swat is earlier than 0:3.0.10-1.4E.12.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354022" version="503" comment="samba-client is earlier than 0:3.0.10-1.4E.12.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070354023" version="503" comment="samba-common is earlier than 0:3.0.10-1.4E.12.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070354008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356002" version="504" comment="libpng is earlier than 2:1.2.10-7.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356003" version="504" comment="libpng is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356004" version="504" comment="libpng-devel is earlier than 2:1.2.10-7.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356005" version="504" comment="libpng-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356007" version="504" comment="libpng is earlier than 2:1.2.2-27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356008" version="504" comment="libpng is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356009" version="504" comment="libpng-devel is earlier than 2:1.2.2-27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356010" version="504" comment="libpng-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356011" version="504" comment="libpng10 is earlier than 0:1.0.13-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356012" version="504" comment="libpng10 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356013" version="504" comment="libpng10-devel is earlier than 0:1.0.13-17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356014" version="504" comment="libpng10-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356016" version="504" comment="libpng is earlier than 2:1.2.7-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356017" version="504" comment="libpng-devel is earlier than 2:1.2.7-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356018" version="504" comment="libpng10 is earlier than 0:1.0.16-3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070356019" version="504" comment="libpng10-devel is earlier than 0:1.0.16-3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070356005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070356010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070358002" version="503" comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070358004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070358003" version="503" comment="squirrelmail is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070358005" version="503" comment="squirrelmail is earlier than 0:1.4.8-6.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070358006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070358008" version="503" comment="squirrelmail is earlier than 0:1.4.8-4.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070022002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070358008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368002" version="505" comment="tcpdump is earlier than 14:3.9.4-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070368003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368003" version="505" comment="tcpdump is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368004" version="505" comment="arpwatch is earlier than 14:2.1a13-18.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070368004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368005" version="505" comment="arpwatch is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368006" version="505" comment="libpcap is earlier than 14:0.9.4-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070368005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368007" version="505" comment="libpcap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368008" version="505" comment="libpcap-devel is earlier than 14:0.9.4-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070368005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070368009" version="505" comment="libpcap-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376002" version="502" comment="kernel is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376004" version="502" comment="kernel-headers is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376006" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376008" version="502" comment="kernel-devel is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376010" version="502" comment="kernel-xen is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376012" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376014" version="502" comment="kernel-kdump is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376016" version="502" comment="kernel-PAE is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376018" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070376020" version="502" comment="kernel-doc is earlier than 0:2.6.18-8.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070376003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070384002" version="502" comment="krb5 is earlier than 0:1.2.7-66" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070384004" version="502" comment="krb5-server is earlier than 0:1.2.7-66" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070384006" version="502" comment="krb5-devel is earlier than 0:1.2.7-66" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070384008" version="502" comment="krb5-libs is earlier than 0:1.2.7-66" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070384010" version="502" comment="krb5-workstation is earlier than 0:1.2.7-66" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070384003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070385002" version="504" comment="fetchmail is earlier than 0:6.3.6-1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070385004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070385003" version="504" comment="fetchmail is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070385005" version="504" comment="fetchmail is earlier than 0:6.2.0-3.el3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070385006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070385008" version="504" comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070385008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070386002" version="503" comment="mutt is earlier than 5:1.4.2.2-3.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070386002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070386004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070386003" version="503" comment="mutt is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070386002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070386005" version="503" comment="mutt is earlier than 5:1.4.1-5.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070386002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070386006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070386006" version="503" comment="mutt is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070386002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070386008" version="503" comment="mutt is earlier than 5:1.4.1-12.0.3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070386002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070386008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387002" version="503" comment="tcpdump is earlier than 14:3.8.2-12.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070387003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387003" version="503" comment="tcpdump is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387004" version="503" comment="arpwatch is earlier than 14:2.1a13-12.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070387004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387005" version="503" comment="arpwatch is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387006" version="503" comment="libpcap is earlier than 14:0.8.3-12.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070387005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070387007" version="503" comment="libpcap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070368004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389002" version="503" comment="quagga is earlier than 0:0.98.6-2.1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389003" version="503" comment="quagga is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389004" version="503" comment="quagga-contrib is earlier than 0:0.98.6-2.1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389005" version="503" comment="quagga-contrib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389006" version="503" comment="quagga-devel is earlier than 0:0.98.6-2.1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389007" version="503" comment="quagga-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389009" version="503" comment="quagga is earlier than 0:0.96.2-12.3E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389010" version="503" comment="quagga is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389011" version="503" comment="quagga-devel is earlier than 0:0.96.2-12.3E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389012" version="503" comment="quagga-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389013" version="503" comment="quagga-contrib is earlier than 0:0.96.2-12.3E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389014" version="503" comment="quagga-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389016" version="503" comment="quagga is earlier than 0:0.98.3-2.4.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389017" version="503" comment="quagga-devel is earlier than 0:0.98.3-2.4.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070389018" version="503" comment="quagga-contrib is earlier than 0:0.98.3-2.4.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070389003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070389008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070391002" version="503" comment="file is earlier than 0:4.17-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070391004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070391005" version="503" comment="file is earlier than 0:4.10-3.0.2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070124002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070391006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395002" version="503" comment="mod_perl is earlier than 0:2.0.2-6.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395003" version="503" comment="mod_perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395004" version="503" comment="mod_perl-devel is earlier than 0:2.0.2-6.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395005" version="503" comment="mod_perl-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395007" version="503" comment="mod_perl is earlier than 0:1.99_09-12.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395008" version="503" comment="mod_perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395009" version="503" comment="mod_perl-devel is earlier than 0:1.99_09-12.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395010" version="503" comment="mod_perl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395012" version="503" comment="mod_perl is earlier than 0:1.99_16-4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070395013" version="503" comment="mod_perl-devel is earlier than 0:1.99_16-4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070395003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070395008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400002" version="503" comment="devhelp is earlier than 0:0.12-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400004" version="503" comment="devhelp-devel is earlier than 0:0.12-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400006" version="503" comment="firefox is earlier than 0:1.5.0.12-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400008" version="503" comment="firefox-devel is earlier than 0:1.5.0.12-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400010" version="503" comment="yelp is earlier than 0:2.16.0-15.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070400013" version="503" comment="firefox is earlier than 0:1.5.0.12-0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070401002" version="503" comment="thunderbird is earlier than 0:1.5.0.12-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070401005" version="503" comment="thunderbird is earlier than 0:1.5.0.12-0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070400008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402002" version="503" comment="seamonkey is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402004" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402006" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402008" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402010" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402012" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402014" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402016" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402018" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402020" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.1.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402023" version="503" comment="seamonkey is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402024" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402025" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402026" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402027" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402028" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402029" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402030" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402031" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402032" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402033" version="503" comment="devhelp is earlier than 0:0.10-0.8.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070402035" version="503" comment="devhelp-devel is earlier than 0:0.10-0.8.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070402006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403002" version="503" comment="freetype is earlier than 0:2.2.1-19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403004" version="503" comment="freetype-demos is earlier than 0:2.2.1-19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403006" version="503" comment="freetype-devel is earlier than 0:2.2.1-19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403009" version="503" comment="freetype is earlier than 0:2.1.4-7.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403011" version="503" comment="freetype-devel is earlier than 0:2.1.4-7.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403013" version="503" comment="freetype-utils is earlier than 0:2.1.4-7.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403015" version="503" comment="freetype-demos is earlier than 0:2.1.4-7.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403018" version="503" comment="freetype is earlier than 0:2.1.9-6.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403019" version="503" comment="freetype-devel is earlier than 0:2.1.9-6.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403020" version="503" comment="freetype-demos is earlier than 0:2.1.9-6.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070403021" version="503" comment="freetype-utils is earlier than 0:2.1.9-6.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070150005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070403008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406002" version="502" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406004" version="502" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406006" version="502" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406008" version="502" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406010" version="502" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406012" version="502" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406014" version="502" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406016" version="502" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406018" version="502" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406020" version="502" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406022" version="502" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406024" version="502" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406026" version="502" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406028" version="502" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406030" version="502" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406032" version="502" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406034" version="502" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406036" version="502" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406038" version="502" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406040" version="502" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406042" version="502" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406044" version="502" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406046" version="502" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406048" version="502" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406050" version="502" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406052" version="502" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406054" version="502" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406056" version="502" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406058" version="502" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406060" version="502" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406062" version="502" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406064" version="502" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406066" version="502" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406068" version="502" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406070" version="502" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406072" version="502" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406074" version="502" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406076" version="502" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406078" version="502" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406080" version="502" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406082" version="502" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406084" version="502" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406086" version="502" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406088" version="502" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406090" version="502" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406092" version="502" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406094" version="502" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406096" version="502" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406098" version="502" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406100" version="502" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406102" version="502" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406104" version="502" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406106" version="502" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406108" version="502" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406110" version="502" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406112" version="502" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406114" version="502" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406116" version="502" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406118" version="502" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406120" version="502" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406122" version="502" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406124" version="502" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406126" version="502" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406128" version="502" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406130" version="502" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406132" version="502" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406134" version="502" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406136" version="502" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406138" version="502" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406140" version="502" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406142" version="502" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406144" version="502" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406146" version="502" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406148" version="502" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406151" version="502" comment="openoffice.org is earlier than 0:1.1.2-39.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406153" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-39.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406155" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-39.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406158" version="502" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406159" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406160" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406162" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.1.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406163" version="502" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406164" version="502" comment="openoffice.org2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406165" version="502" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406080" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406166" version="502" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406080" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406167" version="502" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406168" version="502" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406169" version="502" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406170" version="502" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406171" version="502" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406172" version="502" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406173" version="502" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406084" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406174" version="502" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406084" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406175" version="502" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406176" version="502" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406177" version="502" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406086" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406178" version="502" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406086" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406179" version="502" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406180" version="502" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406181" version="502" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406088" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406182" version="502" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406088" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406183" version="502" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406089" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406184" version="502" comment="openoffice.org2-testtools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406089" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406185" version="502" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406090" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406186" version="502" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406090" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406187" version="502" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406188" version="502" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406189" version="502" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406190" version="502" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406191" version="502" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406093" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406192" version="502" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406093" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406193" version="502" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406094" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406194" version="502" comment="openoffice.org2-langpack-it is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406094" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406195" version="502" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406095" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406196" version="502" comment="openoffice.org2-pyuno is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406095" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406197" version="502" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406096" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406198" version="502" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406096" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406199" version="502" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406200" version="502" comment="openoffice.org2-javafilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406201" version="502" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406202" version="502" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406203" version="502" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406099" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406204" version="502" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406099" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406205" version="502" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406100" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406206" version="502" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406100" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406207" version="502" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406101" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406208" version="502" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406101" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406209" version="502" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406102" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406210" version="502" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406102" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406211" version="502" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406103" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406212" version="502" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406103" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406213" version="502" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406214" version="502" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406215" version="502" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406105" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406216" version="502" comment="openoffice.org2-math is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406105" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406217" version="502" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406218" version="502" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406219" version="502" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406220" version="502" comment="openoffice.org2-impress is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406221" version="502" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406222" version="502" comment="openoffice.org2-langpack-es is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406223" version="502" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406109" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406224" version="502" comment="openoffice.org2-calc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406109" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406225" version="502" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406226" version="502" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406227" version="502" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406228" version="502" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406229" version="502" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406230" version="502" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406231" version="502" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406113" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406232" version="502" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406113" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406233" version="502" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406114" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406234" version="502" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406114" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406235" version="502" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406115" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406236" version="502" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406115" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406237" version="502" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406116" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406238" version="502" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406116" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406239" version="502" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406240" version="502" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406241" version="502" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406242" version="502" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406243" version="502" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406119" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406244" version="502" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406119" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406245" version="502" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406246" version="502" comment="openoffice.org2-core is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406247" version="502" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406248" version="502" comment="openoffice.org2-base is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406249" version="502" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406122" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406250" version="502" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406122" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406251" version="502" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406252" version="502" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406253" version="502" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406254" version="502" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406255" version="502" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406256" version="502" comment="openoffice.org2-emailmerge is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406257" version="502" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406258" version="502" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406259" version="502" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406127" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406260" version="502" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406127" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406261" version="502" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406262" version="502" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406263" version="502" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406129" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406264" version="502" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406129" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406265" version="502" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406130" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406266" version="502" comment="openoffice.org2-writer is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406130" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406267" version="502" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406268" version="502" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406269" version="502" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406270" version="502" comment="openoffice.org2-langpack-de is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406271" version="502" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406133" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406272" version="502" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406133" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406273" version="502" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406134" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406274" version="502" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406134" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406275" version="502" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406135" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406276" version="502" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406135" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406277" version="502" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406136" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406278" version="502" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406136" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406279" version="502" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.1.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406137" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070406009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070406280" version="502" comment="openoffice.org2-draw is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406137" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070430002" version="502" comment="openldap is earlier than 0:2.0.27-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070430004" version="502" comment="openldap-servers is earlier than 0:2.0.27-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070430006" version="502" comment="openldap-devel is earlier than 0:2.0.27-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070430008" version="502" comment="openldap-clients is earlier than 0:2.0.27-23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070310004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070431002" version="502" comment="shadow-utils is earlier than 2:4.0.3-29.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070276002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070431003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436002" version="502" comment="kernel is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436004" version="502" comment="kernel-source is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436005" version="502" comment="kernel-source is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436006" version="502" comment="kernel-smp is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436008" version="502" comment="kernel-doc is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436010" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436011" version="502" comment="kernel-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436012" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436013" version="502" comment="kernel-smp-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436014" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436015" version="502" comment="kernel-BOOT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436016" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436018" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-50.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070436003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070436019" version="502" comment="kernel-hugemem-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465002" version="502" comment="pam is earlier than 0:0.75-72" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465003" version="502" comment="pam is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465004" version="502" comment="pam-devel is earlier than 0:0.75-72" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465005" version="502" comment="pam-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465006" version="502" comment="cdrtools is earlier than 8:2.01.0.a32-0.EL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465007" version="502" comment="cdrtools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465008" version="502" comment="mkisofs is earlier than 8:2.01.0.a32-0.EL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465009" version="502" comment="mkisofs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465010" version="502" comment="cdrecord-devel is earlier than 8:2.01.0.a32-0.EL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465011" version="502" comment="cdrecord-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465012" version="502" comment="cdda2wav is earlier than 8:2.01.0.a32-0.EL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465013" version="502" comment="cdda2wav is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465014" version="502" comment="cdrecord is earlier than 8:2.01.0.a32-0.EL3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070465004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070465015" version="502" comment="cdrecord is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070469002" version="502" comment="gdb is earlier than 0:6.3.0.0-1.138.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070229002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070469003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473002" version="502" comment="gcc is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473004" version="502" comment="libgcj is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473006" version="502" comment="libgcc is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473008" version="502" comment="libstdc++ is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473010" version="502" comment="gcc-c++ is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473012" version="502" comment="gcc-g77 is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473014" version="502" comment="gcc-objc is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473016" version="502" comment="libgnat is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473018" version="502" comment="libobjc is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473020" version="502" comment="gcc-c++-ppc32 is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473022" version="502" comment="libstdc++-devel is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473024" version="502" comment="libgcj-devel is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473026" version="502" comment="gcc-java is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473028" version="502" comment="gcc-gnat is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473030" version="502" comment="libf2c is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473032" version="502" comment="gcc-ppc32 is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070473034" version="502" comment="cpp is earlier than 0:3.2.3-59" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070220012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488002" version="504" comment="kernel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488004" version="504" comment="kernel-devel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488006" version="504" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488008" version="504" comment="kernel-xenU is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488009" version="504" comment="kernel-xenU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488010" version="504" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488011" version="504" comment="kernel-xenU-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488012" version="504" comment="kernel-smp is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488014" version="504" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488016" version="504" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488018" version="504" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488020" version="504" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070488022" version="504" comment="kernel-doc is earlier than 0:2.6.9-55.0.2.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070488003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070492002" version="503" comment="spamassassin is earlier than 0:3.1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070492004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070492005" version="503" comment="spamassassin is earlier than 0:3.1.9-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070074002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070492006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494002" version="503" comment="kdebase is earlier than 6:3.5.4-13.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494003" version="503" comment="kdebase is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494004" version="503" comment="kdebase-devel is earlier than 6:3.5.4-13.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494005" version="503" comment="kdebase-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494007" version="503" comment="kdebase is earlier than 6:3.1.3-5.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494008" version="503" comment="kdebase is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494009" version="503" comment="kdebase-devel is earlier than 6:3.1.3-5.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494010" version="503" comment="kdebase-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494012" version="503" comment="kdebase is earlier than 6:3.3.1-5.19.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070494013" version="503" comment="kdebase-devel is earlier than 6:3.3.1-5.19.rhel4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070494003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070494008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070497002" version="502" comment="iscsi-initiator-utils is earlier than 0:6.2.0.742-0.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070497003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070497003" version="502" comment="iscsi-initiator-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501002" version="503" comment="libexif is earlier than 0:0.6.13-4.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070501004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501003" version="503" comment="libexif is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501004" version="503" comment="libexif-devel is earlier than 0:0.6.13-4.0.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070501004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501005" version="503" comment="libexif-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501007" version="503" comment="libexif is earlier than 0:0.5.12-5.1.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070501006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501008" version="503" comment="libexif is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501009" version="503" comment="libexif-devel is earlier than 0:0.5.12-5.1.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070501006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070501010" version="503" comment="libexif-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070501003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070509002" version="503" comment="evolution is earlier than 0:1.4.5-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070509003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070509004" version="503" comment="evolution-devel is earlier than 0:1.4.5-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070509003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070509007" version="503" comment="evolution is earlier than 0:2.0.2-35.0.4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070509005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070509008" version="503" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070158003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070509005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070510002" version="502" comment="evolution-data-server is earlier than 0:1.8.0-15.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070510003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070510004" version="502" comment="evolution-data-server-devel is earlier than 0:1.8.0-15.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070510003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513002" version="503" comment="gimp is earlier than 2:2.2.13-2.0.7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513004" version="503" comment="gimp-libs is earlier than 2:2.2.13-2.0.7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513006" version="503" comment="gimp-devel is earlier than 2:2.2.13-2.0.7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513009" version="503" comment="gimp is earlier than 1:1.2.3-20.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513011" version="503" comment="gimp-perl is earlier than 1:1.2.3-20.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513013" version="503" comment="gimp-devel is earlier than 1:1.2.3-20.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513016" version="503" comment="gimp is earlier than 1:2.0.5-7.0.7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070513017" version="503" comment="gimp-devel is earlier than 1:2.0.5-7.0.7.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070343003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070513008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519002" version="503" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519004" version="503" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519006" version="503" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519008" version="503" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519010" version="503" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519012" version="503" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519014" version="503" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519016" version="503" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519018" version="503" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519020" version="503" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519022" version="503" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519024" version="503" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519026" version="503" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519028" version="503" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519030" version="503" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519032" version="503" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519034" version="503" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070519036" version="503" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070520002" version="502" comment="xorg-x11-xfs is earlier than 1:1.0.2-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070520003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070520003" version="502" comment="xorg-x11-xfs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070520004" version="502" comment="xorg-x11-xfs-utils is earlier than 1:1.0.2-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070520003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070520003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070520005" version="502" comment="xorg-x11-xfs-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070520003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533002" version="502" comment="httpd is earlier than 0:2.0.46-67.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070533003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533003" version="502" comment="httpd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533004" version="502" comment="mod_ssl is earlier than 0:2.0.46-67.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070533003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533005" version="502" comment="mod_ssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533006" version="502" comment="httpd-devel is earlier than 0:2.0.46-67.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070533003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070533007" version="502" comment="httpd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534002" version="503" comment="httpd is earlier than 0:2.0.52-32.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070534003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534004" version="503" comment="httpd-manual is earlier than 0:2.0.52-32.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070534003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534005" version="503" comment="httpd-manual is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534006" version="503" comment="mod_ssl is earlier than 0:2.0.52-32.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070534003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534008" version="503" comment="httpd-devel is earlier than 0:2.0.52-32.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070534003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534010" version="503" comment="httpd-suexec is earlier than 0:2.0.52-32.2.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070534003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070534011" version="503" comment="httpd-suexec is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070539002" version="502" comment="aide is earlier than 0:0.13.1-2.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070539002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070539003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070539003" version="502" comment="aide is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070539002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540002" version="505" comment="openssh is earlier than 0:4.3p2-24.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070540003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540003" version="505" comment="openssh is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540004" version="505" comment="openssh-server is earlier than 0:4.3p2-24.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070540003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540005" version="505" comment="openssh-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540006" version="505" comment="openssh-clients is earlier than 0:4.3p2-24.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070540003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540007" version="505" comment="openssh-clients is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540008" version="505" comment="openssh-askpass is earlier than 0:4.3p2-24.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070540003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070540009" version="505" comment="openssh-askpass is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070542002" version="506" comment="mcstrans is earlier than 0:0.2.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070542002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070542003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070542003" version="506" comment="mcstrans is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070542002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070555002" version="505" comment="pam is earlier than 0:0.99.6.2-3.26.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070555003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070555003" version="505" comment="pam is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070555004" version="505" comment="pam-devel is earlier than 0:0.99.6.2-3.26.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070555003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070555005" version="505" comment="pam-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556002" version="502" comment="httpd is earlier than 0:2.2.3-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070556003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556003" version="502" comment="httpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556004" version="502" comment="httpd-devel is earlier than 0:2.2.3-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070556003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556005" version="502" comment="httpd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556006" version="502" comment="mod_ssl is earlier than 0:2.2.3-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070556003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556007" version="502" comment="mod_ssl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556008" version="502" comment="httpd-manual is earlier than 0:2.2.3-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070556003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070556009" version="502" comment="httpd-manual is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070559002" version="502" comment="cman is earlier than 0:2.0.64-1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070559002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070559003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070559003" version="502" comment="cman is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070559002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070559004" version="502" comment="cman-devel is earlier than 0:2.0.64-1.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070559003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070559003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070559005" version="502" comment="cman-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070559003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562002" version="503" comment="krb5 is earlier than 0:1.5-26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562004" version="503" comment="krb5-devel is earlier than 0:1.5-26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562006" version="503" comment="krb5-workstation is earlier than 0:1.5-26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562008" version="503" comment="krb5-libs is earlier than 0:1.5-26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562010" version="503" comment="krb5-server is earlier than 0:1.5-26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562013" version="503" comment="krb5 is earlier than 0:1.3.4-49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562015" version="503" comment="krb5-workstation is earlier than 0:1.3.4-49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562017" version="503" comment="krb5-devel is earlier than 0:1.3.4-49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562019" version="503" comment="krb5-libs is earlier than 0:1.3.4-49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070562021" version="503" comment="krb5-server is earlier than 0:1.3.4-49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070095006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070562006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569002" version="502" comment="tomcat5 is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569004" version="502" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569006" version="502" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569008" version="502" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569010" version="502" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569012" version="502" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569014" version="502" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569016" version="502" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569018" version="502" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569020" version="502" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070569022" version="502" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.1.0.4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070327012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595002" version="502" comment="kernel is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595004" version="502" comment="kernel-headers is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595006" version="502" comment="kernel-xen is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595008" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595010" version="502" comment="kernel-devel is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595012" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595014" version="502" comment="kernel-kdump is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595016" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595018" version="502" comment="kernel-PAE is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070595020" version="502" comment="kernel-doc is earlier than 0:2.6.18-8.1.8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070595003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070605002" version="503" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070605002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070605003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070605003" version="503" comment="HelixPlayer is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070605002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070605004" version="503" comment="HelixPlayer is earlier than 1:1.0.6-0.EL4.2.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070605002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070605004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070631002" version="505" comment="coolkey is earlier than 0:1.1.0-5.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070631002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070631003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070631003" version="505" comment="coolkey is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070631002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070631004" version="505" comment="coolkey-devel is earlier than 0:1.1.0-5.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070631003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070631003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070631005" version="505" comment="coolkey-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070631003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640002" version="506" comment="conga is earlier than 0:0.10.0-6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070640003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640003" version="506" comment="conga is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640004" version="506" comment="luci is earlier than 0:0.10.0-6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070640003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640005" version="506" comment="luci is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640006" version="506" comment="ricci is earlier than 0:0.10.0-6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070640003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070640007" version="506" comment="ricci is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070640004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662002" version="503" comment="httpd is earlier than 0:2.0.46-68.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662004" version="503" comment="httpd-devel is earlier than 0:2.0.46-68.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662006" version="503" comment="mod_ssl is earlier than 0:2.0.46-68.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662009" version="503" comment="httpd is earlier than 0:2.0.52-32.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662010" version="503" comment="httpd-suexec is earlier than 0:2.0.52-32.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662012" version="503" comment="mod_ssl is earlier than 0:2.0.52-32.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662013" version="503" comment="httpd-manual is earlier than 0:2.0.52-32.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070662015" version="503" comment="httpd-devel is earlier than 0:2.0.52-32.3.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070662005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671002" version="502" comment="kernel is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671004" version="502" comment="kernel-doc is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671006" version="502" comment="kernel-smp is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671008" version="502" comment="kernel-source is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671010" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671012" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671014" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671016" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070671018" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-51.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070436010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070671003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070674002" version="502" comment="perl-Net-DNS is earlier than 0:0.59-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070674002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070674004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070674003" version="502" comment="perl-Net-DNS is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070674002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070674005" version="502" comment="perl-Net-DNS is earlier than 0:0.31-4.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070674002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070674006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070674006" version="502" comment="perl-Net-DNS is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070674002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070675002" version="503" comment="perl-Net-DNS is earlier than 0:0.48-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070674002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070675003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070696002" version="502" comment="flash-plugin is earlier than 0:9.0.48.0-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070696002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070696004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070696003" version="502" comment="flash-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070696002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070701002" version="503" comment="xterm is earlier than 0:192-8.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070701002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070701003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070701003" version="503" comment="xterm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070701002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070703002" version="503" comment="openssh is earlier than 0:3.9p1-8.RHEL4.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070703003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070703004" version="503" comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070703003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070703006" version="503" comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070703003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070703008" version="503" comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070703003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070703010" version="503" comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070703003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705002" version="502" comment="kernel is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705004" version="502" comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705006" version="502" comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705008" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705010" version="502" comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705012" version="502" comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705014" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705016" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705018" version="502" comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070099010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070705020" version="502" comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070705003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070709002" version="503" comment="wireshark is earlier than 0:0.99.6-EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070709003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070709004" version="503" comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070709003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070710002" version="505" comment="wireshark is earlier than 0:0.99.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070710003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070710004" version="505" comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070066003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070710003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720002" version="503" comment="cups is earlier than 1:1.2.4-11.5.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720004" version="503" comment="cups-lpd is earlier than 1:1.2.4-11.5.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720006" version="503" comment="cups-devel is earlier than 1:1.2.4-11.5.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720008" version="503" comment="cups-libs is earlier than 1:1.2.4-11.5.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720011" version="503" comment="cups is earlier than 1:1.1.17-13.3.45" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720013" version="503" comment="cups-devel is earlier than 1:1.1.17-13.3.45" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720015" version="503" comment="cups-libs is earlier than 1:1.1.17-13.3.45" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720018" version="503" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720019" version="503" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070720020" version="503" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070720008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721002" version="504" comment="qt is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721003" version="504" comment="qt is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721004" version="504" comment="qt-ODBC is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721005" version="504" comment="qt-ODBC is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721006" version="504" comment="qt-config is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721007" version="504" comment="qt-config is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721008" version="504" comment="qt-designer is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721009" version="504" comment="qt-designer is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721010" version="504" comment="qt-PostgreSQL is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721011" version="504" comment="qt-PostgreSQL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721012" version="504" comment="qt-MySQL is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721013" version="504" comment="qt-MySQL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721014" version="504" comment="qt-devel-docs is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721015" version="504" comment="qt-devel-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721016" version="504" comment="qt-devel is earlier than 1:3.3.6-21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721017" version="504" comment="qt-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721019" version="504" comment="qt is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721020" version="504" comment="qt is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721021" version="504" comment="qt-PostgreSQL is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721022" version="504" comment="qt-PostgreSQL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721023" version="504" comment="qt-designer is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721024" version="504" comment="qt-designer is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721025" version="504" comment="qt-devel is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721026" version="504" comment="qt-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721027" version="504" comment="qt-MySQL is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721028" version="504" comment="qt-MySQL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721029" version="504" comment="qt-config is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721030" version="504" comment="qt-config is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721031" version="504" comment="qt-ODBC is earlier than 1:3.1.2-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721032" version="504" comment="qt-ODBC is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721034" version="504" comment="qt is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721035" version="504" comment="qt-devel is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721036" version="504" comment="qt-MySQL is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721037" version="504" comment="qt-designer is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721038" version="504" comment="qt-PostgreSQL is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721039" version="504" comment="qt-config is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070721040" version="504" comment="qt-ODBC is earlier than 1:3.3.3-11.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070721003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070721008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722002" version="503" comment="seamonkey is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722004" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722006" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722008" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722010" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722012" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722014" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722016" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722018" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722020" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722023" version="503" comment="seamonkey is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722024" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722025" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722026" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722027" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722028" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722029" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722030" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722031" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070722032" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070077003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070722005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070723002" version="502" comment="thunderbird is earlier than 0:1.5.0.12-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070723004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070723005" version="502" comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070078002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070723006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070724002" version="503" comment="firefox is earlier than 0:1.5.0.12-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070723004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070724004" version="503" comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070097006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070723004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070724007" version="503" comment="firefox is earlier than 0:1.5.0.12-0.3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070079002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070723006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729002" version="503" comment="kdegraphics is earlier than 7:3.5.4-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070729004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729003" version="503" comment="kdegraphics is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729004" version="503" comment="kdegraphics-devel is earlier than 7:3.5.4-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070729004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729005" version="503" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729007" version="503" comment="kdegraphics is earlier than 7:3.3.1-4.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070729006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729008" version="503" comment="kdegraphics is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729009" version="503" comment="kdegraphics-devel is earlier than 7:3.3.1-4.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070729006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070729010" version="503" comment="kdegraphics-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070729003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070730002" version="503" comment="gpdf is earlier than 0:2.8.2-7.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070730002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070730003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070730003" version="503" comment="gpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070730002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731002" version="502" comment="tetex is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731003" version="502" comment="tetex is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731004" version="502" comment="tetex-latex is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731005" version="502" comment="tetex-latex is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731006" version="502" comment="tetex-xdvi is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731007" version="502" comment="tetex-xdvi is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731008" version="502" comment="tetex-doc is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731009" version="502" comment="tetex-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731010" version="502" comment="tetex-dvips is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731011" version="502" comment="tetex-dvips is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731012" version="502" comment="tetex-fonts is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731013" version="502" comment="tetex-fonts is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731014" version="502" comment="tetex-afm is earlier than 0:3.0-33.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731015" version="502" comment="tetex-afm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731017" version="502" comment="tetex is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731018" version="502" comment="tetex is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731019" version="502" comment="tetex-latex is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731020" version="502" comment="tetex-latex is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731021" version="502" comment="tetex-dvips is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731022" version="502" comment="tetex-dvips is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731023" version="502" comment="tetex-doc is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731024" version="502" comment="tetex-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731025" version="502" comment="tetex-xdvi is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731026" version="502" comment="tetex-xdvi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731027" version="502" comment="tetex-afm is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731028" version="502" comment="tetex-afm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731029" version="502" comment="tetex-fonts is earlier than 0:1.0.7-67.10" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731030" version="502" comment="tetex-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731032" version="502" comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731033" version="502" comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731034" version="502" comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731035" version="502" comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731036" version="502" comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731037" version="502" comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070731038" version="502" comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070731003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070731008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732002" version="502" comment="poppler is earlier than 0:0.5.4-4.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070732003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732003" version="502" comment="poppler is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732004" version="502" comment="poppler-devel is earlier than 0:0.5.4-4.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070732003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732005" version="502" comment="poppler-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732006" version="502" comment="poppler-utils is earlier than 0:0.5.4-4.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070732003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070732007" version="502" comment="poppler-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070732004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070735002" version="503" comment="xpdf is earlier than 1:2.02-10.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070735002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070735003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070735003" version="503" comment="xpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070735002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070735005" version="503" comment="xpdf is earlier than 1:3.00-12.RHEL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070735002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070735005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070737002" version="503" comment="pam is earlier than 0:0.77-66.23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070737003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070737004" version="503" comment="pam-devel is earlier than 0:0.77-66.23" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070465003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070737003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740002" version="503" comment="bind is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740004" version="503" comment="bind-sdb is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740006" version="503" comment="bind-utils is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740008" version="503" comment="caching-nameserver is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740010" version="503" comment="bind-devel is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740012" version="503" comment="bind-libbind-devel is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070057008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740014" version="503" comment="bind-libs is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740016" version="503" comment="bind-chroot is earlier than 30:9.3.3-9.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740019" version="503" comment="bind is earlier than 20:9.2.4-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740021" version="503" comment="bind-utils is earlier than 20:9.2.4-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740023" version="503" comment="bind-chroot is earlier than 20:9.2.4-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740025" version="503" comment="bind-libs is earlier than 20:9.2.4-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740027" version="503" comment="bind-devel is earlier than 20:9.2.4-21.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740030" version="503" comment="bind is earlier than 20:9.2.4-27.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740031" version="503" comment="bind-chroot is earlier than 20:9.2.4-27.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740032" version="503" comment="bind-utils is earlier than 20:9.2.4-27.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740033" version="503" comment="bind-libs is earlier than 20:9.2.4-27.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070740034" version="503" comment="bind-devel is earlier than 20:9.2.4-27.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070044003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070740008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070746002" version="505" comment="httpd is earlier than 0:2.2.3-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070746003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070746004" version="505" comment="httpd-manual is earlier than 0:2.2.3-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070746003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070746006" version="505" comment="mod_ssl is earlier than 0:2.2.3-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070746003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070746008" version="505" comment="httpd-devel is earlier than 0:2.2.3-11.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070746003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070747002" version="503" comment="httpd is earlier than 0:2.0.52-38.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070747003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070747004" version="503" comment="httpd-suexec is earlier than 0:2.0.52-38.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070747003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070747006" version="503" comment="httpd-devel is earlier than 0:2.0.52-38.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070747003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070747008" version="503" comment="mod_ssl is earlier than 0:2.0.52-38.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070747003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070747010" version="503" comment="httpd-manual is earlier than 0:2.0.52-38.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070534003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070747003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070765002" version="503" comment="libgtop2 is earlier than 0:2.8.0-1.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070765002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070765003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070765003" version="503" comment="libgtop2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070765002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070765004" version="503" comment="libgtop2-devel is earlier than 0:2.8.0-1.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070765003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070765003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070765005" version="503" comment="libgtop2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070765003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774002" version="502" comment="kernel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774004" version="502" comment="kernel-devel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774006" version="502" comment="kernel-smp is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774008" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774010" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774012" version="502" comment="kernel-xenU is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774014" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070488006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774016" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070774022" version="502" comment="kernel-doc is earlier than 0:2.6.9-55.0.6.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070774003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070777002" version="502" comment="gdm is earlier than 1:2.16.0-31.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070286002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070777003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070777003" version="502" comment="gdm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070286002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070779002" version="503" comment="mailman is earlier than 3:2.1.5.1-34.rhel4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070779002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070779003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070779003" version="503" comment="mailman is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070779002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795002" version="503" comment="cyrus-sasl is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795003" version="503" comment="cyrus-sasl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795004" version="503" comment="cyrus-sasl-md5 is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795005" version="503" comment="cyrus-sasl-md5 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795006" version="503" comment="cyrus-sasl-devel is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795007" version="503" comment="cyrus-sasl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795008" version="503" comment="cyrus-sasl-ntlm is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795009" version="503" comment="cyrus-sasl-ntlm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795010" version="503" comment="cyrus-sasl-gssapi is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795011" version="503" comment="cyrus-sasl-gssapi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795012" version="503" comment="cyrus-sasl-plain is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795013" version="503" comment="cyrus-sasl-plain is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795014" version="503" comment="cyrus-sasl-sql is earlier than 0:2.1.19-14" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070795003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070795015" version="503" comment="cyrus-sasl-sql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070795008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813002" version="502" comment="openssl is earlier than 0:0.9.7a-33.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070813003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813003" version="502" comment="openssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813004" version="502" comment="openssl-devel is earlier than 0:0.9.7a-33.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070813003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813005" version="502" comment="openssl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813006" version="502" comment="openssl-perl is earlier than 0:0.9.7a-33.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070813003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070813007" version="502" comment="openssl-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070813004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817002" version="502" comment="java-1.4.2-ibm is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817004" version="502" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817006" version="502" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817008" version="502" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817010" version="502" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817012" version="502" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070817014" version="502" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.9-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070166008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070817004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829002" version="502" comment="java-1.5.0-ibm is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829004" version="502" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829006" version="502" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829008" version="502" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829010" version="502" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829012" version="502" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070829014" version="502" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.5-1jpp.0.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070167006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070829004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845002" version="504" comment="libvorbis is earlier than 1:1.1.2-3.el5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845003" version="504" comment="libvorbis is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845004" version="504" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845005" version="504" comment="libvorbis-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070055001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845007" version="504" comment="libvorbis is earlier than 1:1.0-8.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845008" version="504" comment="libvorbis is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845009" version="504" comment="libvorbis-devel is earlier than 1:1.0-8.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845010" version="504" comment="libvorbis-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070001001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845012" version="504" comment="libvorbis is earlier than 1:1.1.0-2.el4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070845013" version="504" comment="libvorbis-devel is earlier than 1:1.1.0-2.el4.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070845003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070845008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848002" version="502" comment="openoffice.org is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848004" version="502" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848006" version="502" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848008" version="502" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848010" version="502" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848012" version="502" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848014" version="502" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848016" version="502" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848018" version="502" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848020" version="502" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848022" version="502" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848024" version="502" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848026" version="502" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848028" version="502" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848030" version="502" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848032" version="502" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848034" version="502" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848036" version="502" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848038" version="502" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848040" version="502" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848042" version="502" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848044" version="502" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848046" version="502" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848048" version="502" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848050" version="502" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848052" version="502" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848054" version="502" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848056" version="502" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848058" version="502" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848060" version="502" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848062" version="502" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848064" version="502" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848066" version="502" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848068" version="502" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848070" version="502" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848072" version="502" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848074" version="502" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848076" version="502" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848078" version="502" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848080" version="502" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848082" version="502" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848084" version="502" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848086" version="502" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848088" version="502" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848090" version="502" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848092" version="502" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848094" version="502" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848096" version="502" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848098" version="502" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848100" version="502" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848102" version="502" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848104" version="502" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848106" version="502" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848108" version="502" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848110" version="502" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848112" version="502" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848114" version="502" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848116" version="502" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848118" version="502" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848120" version="502" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848122" version="502" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848124" version="502" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848126" version="502" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848128" version="502" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848130" version="502" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848132" version="502" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848134" version="502" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848136" version="502" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848138" version="502" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848140" version="502" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848142" version="502" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848144" version="502" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848146" version="502" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848148" version="502" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070069019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848151" version="502" comment="openoffice.org is earlier than 0:1.1.2-40.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848153" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-40.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848155" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-40.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848158" version="502" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.2.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848159" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.2.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848161" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.2.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848162" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.2.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070001004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848163" version="502" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848165" version="502" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848167" version="502" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406135" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848169" version="502" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848171" version="502" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848173" version="502" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848175" version="502" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848177" version="502" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848179" version="502" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848181" version="502" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848183" version="502" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848185" version="502" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848187" version="502" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848189" version="502" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848191" version="502" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848193" version="502" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848195" version="502" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848197" version="502" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406137" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848199" version="502" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848201" version="502" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848203" version="502" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848205" version="502" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848207" version="502" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848209" version="502" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848211" version="502" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848213" version="502" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848215" version="502" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848217" version="502" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848219" version="502" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848221" version="502" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.2.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20070406091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20070848009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20070848223" version="502" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.
